3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://primeworld.com |
Path: | / |
PUT /7e3171d6f3b2563.txt HTTP/1.0 Host: primeworld.com Content-Length: 16 72aa57dd98e41b7f |
HTTP/1.1 201 Created Connection: close Date: Thu, 21 Apr 2011 21:05:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Location: http://primeworld.com Content-Length: 0 Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK |
GET /7e3171d6f3b2563.txt HTTP/1.0 Host: primeworld.com |
HTTP/1.1 200 OK Content-Length: 16 Content-Type: text/plain Last-Modified: Thu, 21 Apr 2011 21:05:57 GMT Accept-Ranges: bytes ETag: W/"627fb6e8670cc1:114a" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 21 Apr 2011 21:05:56 GMT Connection: close 72aa57dd98e41b7f |
Severity: | Information |
Confidence: | Firm |
Host: | http://primeworld.com |
Path: | /Default.aspx |
DEBUG /Default.aspx HTTP/1.0 Host: primeworld.com Command: start-debug |
HTTP/1.1 401 Unauthorized Connection: close Date: Thu, 21 Apr 2011 21:05:57 GMT Server: Microsoft-IIS/6.0 WWW-Authenticate: Negotiate WWW-Authenticate: NTLM X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 39 Debug access denied to '/Default.aspx'. |
Severity: | Information |
Confidence: | Certain |
Host: | http://primeworld.com |
Path: | / |
GET / HTTP/1.1 Host: primeworld.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:05:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: starttime=starttime=4/21 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 76272 <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html <meta name="generator" content="Adobe GoLive 6"> <title>pri ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://primeworld.com |
Path: | / |
GET /robots.txt HTTP/1.0 Host: primeworld.com |
HTTP/1.1 200 OK Content-Length: 74 Content-Type: text/plain Last-Modified: Wed, 31 Mar 2010 12:41:36 GMT Accept-Ranges: bytes ETag: "4963b680cfd0ca1:114a" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 21 Apr 2011 21:05:56 GMT Connection: close User-agent: * Disallow: ./Distributor/ Disallow: ./ProductDetails.aspx |