2. Cross-domain Referer leakage
3. Cross-domain script include
4. Private IP addresses disclosed
Severity: | High |
Confidence: | Certain |
Host: | http://www.webranking.eu |
Path: | /trace.axd |
GET /trace.axd HTTP/1.0 Host: www.webranking.eu |
HTTP/1.1 200 OK Connection: close Date: Fri, 31 Dec 2010 19:18:29 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 5047 ...<html> <head> <style type="text/css"> span.tracecontent b { color:white } span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; } span.tracecontent table { clear:l ...[SNIP]... <body> <span class="tracecontent"> <table cellspacing="0" cellpadding="0" border="0" width="100%"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webranking.eu |
Path: | /news-and-articles |
GET /news-and-articles Host: www.webranking.eu Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 31 Dec 2010 19:18:27 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Expires: Thu, 30 Dec 2010 19:18:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 39398 ... <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> H&H Webra ...[SNIP]... <!-- #Wezz Share --> <script type="text/javascript" src="http://ajax ...[SNIP]... <li><a class="no-padding" id="_lpChatBtn" onclick="lpButtonCTTUrl = 'http://server.iad ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webranking.eu |
Path: | /news-and-articles |
GET /news-and-articles Host: www.webranking.eu Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 31 Dec 2010 19:18:26 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Expires: Thu, 30 Dec 2010 19:18:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 39371 ... <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> H&H Webra ...[SNIP]... <!-- #Wezz Share --> <script type="text/javascript" src="http://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webranking.eu |
Path: | /Trace.axd |
GET /Trace.axd?id=0 HTTP/1.1 Host: www.webranking.eu Proxy-Connection: keep-alive Referer: http://www.webranking.eu Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 31 Dec 2010 19:50:58 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 10096 ...<html> <head> <style type="text/css"> span.tracecontent b { color:white } span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; } span.tracecontent table { clear:l ...[SNIP]... <td>192.168.10.7</td> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webranking.eu |
Path: | /news-and-articles |
GET /robots.txt HTTP/1.0 Host: www.webranking.eu |
HTTP/1.1 200 OK Content-Length: 124 Content-Type: text/plain Content-Location: http://www.webranking.eu Last-Modified: Wed, 03 Nov 2010 15:31:26 GMT Accept-Ranges: bytes ETag: "21a7e22d6c7bcb1:356" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Fri, 31 Dec 2010 19:18:28 GMT Connection: close # robots.txt User-agent: * Disallow: /kwwprojects/ Disallow: /en/kwwprojects/ Sitemap: http://www.halvarsson.se |