1. Cross-site scripting (reflected)
1.1. https://www.att.com/olam/a [REST URL parameter 2]
1.2. https://www.att.com/olam/js/cookie.js [REST URL parameter 2]
1.3. https://www.att.com/olam/js/cookie.js [REST URL parameter 3]
1.4. https://www.att.com/olam/js/flash.js [REST URL parameter 2]
1.5. https://www.att.com/olam/js/flash.js [REST URL parameter 3]
1.6. https://www.att.com/olam/js/posUtil.js [REST URL parameter 2]
1.7. https://www.att.com/olam/js/posUtil.js [REST URL parameter 3]
1.8. https://www.att.com/olam/js/registration.js [REST URL parameter 2]
1.9. https://www.att.com/olam/js/registration.js [REST URL parameter 3]
1.10. https://www.att.com/olam/js/sniffer.js [REST URL parameter 2]
1.11. https://www.att.com/olam/js/sniffer.js [REST URL parameter 3]
1.12. https://www.att.com/olam/js/tool-tips.js [REST URL parameter 2]
1.13. https://www.att.com/olam/js/tool-tips.js [REST URL parameter 3]
1.14. https://www.att.com/olam/js/validate.js [REST URL parameter 2]
1.15. https://www.att.com/olam/js/validate.js [REST URL parameter 3]
1.16. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp [REST URL parameter 2]
1.17. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp [REST URL parameter 3]
1.18. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp [REST URL parameter 4]
1.19. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp [REST URL parameter 5]
1.20. https://www.att.com/olam/loginAction.olamexecute [REST URL parameter 2]
1.21. https://www.att.com/olam/registrationAction.olamexecute [REST URL parameter 2]
2. SSL cookie without secure flag set
2.1. https://www.att.com/olam/a
2.2. https://www.att.com/olam/loginAction.olamexecute
2.3. https://www.att.com/olam/logout.olamexecute
2.4. https://www.att.com/olam/registrationAction.olamexecute
2.5. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp
3. Cookie without HttpOnly flag set
3.1. https://www.att.com/olam/a
3.2. https://www.att.com/olam/loginAction.olamexecute
3.3. https://www.att.com/olam/logout.olamexecute
3.4. https://www.att.com/olam/registrationAction.olamexecute
3.5. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp
4. Password field with autocomplete enabled
4.1. https://www.att.com/olam/loginAction.olamexecute
4.2. https://www.att.com/olam/logout.olamexecute
5. Cookie scoped to parent domain
5.1. https://www.att.com/olam/a
5.2. https://www.att.com/olam/jsp/tiles/common_includes/cGateCookie.jsp
5.3. https://www.att.com/olam/loginAction.olamexecute
5.4. https://www.att.com/olam/logout.olamexecute
5.5. https://www.att.com/olam/registrationAction.olamexecute
6. Cross-domain Referer leakage
7.1. https://www.att.com/olam/loginAction.olamexecute
7.2. https://www.att.com/olam/logout.olamexecute
7.3. https://www.att.com/olam/registrationAction.olamexecute
9. Content type incorrectly stated
10. Content type is not specified
10.1. https://www.att.com/olam/js/AC_RunActiveContent.js
10.2. https://www.att.com/olam/js/ATT-Olam-english-mtagconfig.js
10.3. https://www.att.com/olam/js/Ajax.js
10.4. https://www.att.com/olam/js/UserMessaging.js
10.5. https://www.att.com/olam/js/cookie.js
10.6. https://www.att.com/olam/js/cssBrowserSelector.js
10.7. https://www.att.com/olam/js/flash.js
10.8. https://www.att.com/olam/js/gvpUtils.js
10.9. https://www.att.com/olam/js/hideSelect.js
10.10. https://www.att.com/olam/js/posUtil.js
10.11. https://www.att.com/olam/js/prototype.js
10.12. https://www.att.com/olam/js/registration.js
10.13. https://www.att.com/olam/js/sessionTimeout.js
10.14. https://www.att.com/olam/js/sniffer.js
10.15. https://www.att.com/olam/js/tool-tips.js
10.16. https://www.att.com/olam/js/validate.js
10.17. https://www.att.com/olam/js/vidSwitcher.js
10.18. https://www.att.com/olam/jsp/profile/imageupload/BrowserDetect.js
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/a |
GET /olam/a4fed8"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9076 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:35:40 GMT Connection: keep-alive Set-Cookie: TLTHID=0FABE03071271 Set-Cookie: EDOCSSESSIONID=NpT7N <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/cookie.js |
GET /olam/js57233"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9087 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:35 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/cookie.js |
GET /olam/js/cookie.jsf02ed"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9087 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:41 GMT Connection: keep-alive Set-Cookie: TLTHID=AA8770F871251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/flash.js |
GET /olam/js548c4"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9086 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:35 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/flash.js |
GET /olam/js/flash.jsaad5b"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9086 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:40 GMT Connection: keep-alive Set-Cookie: TLTHID=AA6B036471251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/posUtil.js |
GET /olam/jsc4874"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9088 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:34 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/posUtil.js |
GET /olam/js/posUtil.jsb568f"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9088 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:39 GMT Connection: keep-alive Set-Cookie: TLTHID=A9D148FA71251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/registration.js |
GET /olam/js3f296"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9093 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:35 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/registration.js |
GET /olam/js/registration.jsea74f"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9093 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:41 GMT Connection: keep-alive Set-Cookie: TLTHID=AA874D5871251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/sniffer.js |
GET /olam/jsc9dbb"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9088 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:34 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/sniffer.js |
GET /olam/js/sniffer.jsa7f9f"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9087 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:40 GMT Connection: keep-alive Set-Cookie: TLTHID=AA0D523C71251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/tool-tips.js |
GET /olam/js2ed91"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9090 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:35 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/tool-tips.js |
GET /olam/js/tool-tips.js97aac"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9090 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:40 GMT Connection: keep-alive Set-Cookie: TLTHID=AA0D3B6271251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/validate.js |
GET /olam/js6e2da"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9089 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:35 GMT Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/validate.js |
GET /olam/js/validate.jsb30a1"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9089 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:25:40 GMT Connection: keep-alive Set-Cookie: TLTHID=AA0FC86E71251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp7a74e"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9116 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:22 GMT Connection: keep-alive Set-Cookie: TLTHID=7B847E3671251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tilesaec42"><img%20src%3da Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9116 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:25 GMT Connection: keep-alive Set-Cookie: TLTHID=7D6B76C871251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9116 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:28 GMT Connection: keep-alive Set-Cookie: TLTHID=7F62D01671251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Content-Length: 9116 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:32 GMT Connection: keep-alive Set-Cookie: TLTHID=8151776A71251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9098 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:28 GMT Connection: keep-alive Set-Cookie: TLTHID=7F0480B071251 Set-Cookie: EDOCSSESSIONID=m52bN <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/registrationAction |
GET /olam/registrationAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9105 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:24:30 GMT Connection: keep-alive Set-Cookie: TLTHID=8039E25E71251 Set-Cookie: EDOCSSESSIONID=vTT7N <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... <meta name="DCSext.failedurl" content="https://www.att ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/a |
GET /olam/a HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9030 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:32:35 GMT Connection: keep-alive Set-Cookie: TLTHID=A131519471261 Set-Cookie: EDOCSSESSIONID=FpjQN <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/logout.olamexecute |
GET /olam/logout.olamexecute HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:39:47 GMT Connection: keep-alive Set-Cookie: TLTHID=A313761C71271 Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: EDOCSSESSIONID=h0BxN Set-Cookie: stack=doammw08; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Content-Length: 57599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/registrationAction |
GET /olam/registrationAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:17 GMT Connection: keep-alive Set-Cookie: TLTHID=54B4862A71251 Set-Cookie: EDOCSSESSIONID=1Xg6N Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:17 GMT; path=/ Set-Cookie: stack=p1eam1m6; path=/ Content-Length: 31527 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 530 Content-Type: text/html; charset=UTF-8 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:42 GMT Connection: keep-alive Set-Cookie: TLTHID=638F778671251 <html> <body> <form name="myForm"> <input type="hidden" name="userid" size="20" /> <input type="hidden" name="passwor ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/a |
GET /olam/a HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9030 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:32:35 GMT Connection: keep-alive Set-Cookie: TLTHID=A131519471261 Set-Cookie: EDOCSSESSIONID=FpjQN <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/logout.olamexecute |
GET /olam/logout.olamexecute HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:39:47 GMT Connection: keep-alive Set-Cookie: TLTHID=A313761C71271 Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: EDOCSSESSIONID=h0BxN Set-Cookie: stack=doammw08; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Content-Length: 57599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/registrationAction |
GET /olam/registrationAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:17 GMT Connection: keep-alive Set-Cookie: TLTHID=54B4862A71251 Set-Cookie: EDOCSSESSIONID=1Xg6N Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:17 GMT; path=/ Set-Cookie: stack=p1eam1m6; path=/ Content-Length: 31527 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 530 Content-Type: text/html; charset=UTF-8 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:42 GMT Connection: keep-alive Set-Cookie: TLTHID=638F778671251 <html> <body> <form name="myForm"> <input type="hidden" name="userid" size="20" /> <input type="hidden" name="passwor ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </script> <form name="loginActionForm" action="/olam/loginAction <script type="text/javascript" src="/olam/jsp/profile ...[SNIP]... <div id="showPassForInter ...[SNIP]... <div id="doNotShowRegPass"> <input type="password" name="pass" size="21" value="" style="vertical-align ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/logout.olamexecute |
GET /olam/logout.olamexecute HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:39:47 GMT Connection: keep-alive Set-Cookie: TLTHID=A313761C71271 Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: EDOCSSESSIONID=h0BxN Set-Cookie: stack=doammw08; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Content-Length: 57599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </script> <form name="loginActionForm" action="/olam/loginAction <script type="text/javascript" src="/olam/jsp/profile ...[SNIP]... <div id="showPassForInter ...[SNIP]... <div id="doNotShowRegPass"> <input type="password" name="pass" size="21" value="" style="vertical-align ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/a |
GET /olam/a HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 404 Not Found Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie" Content-Length: 9030 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:32:35 GMT Connection: keep-alive Set-Cookie: TLTHID=A131519471261 Set-Cookie: EDOCSSESSIONID=FpjQN <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 530 Content-Type: text/html; charset=UTF-8 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:42 GMT Connection: keep-alive Set-Cookie: TLTHID=638F778671251 <html> <body> <form name="myForm"> <input type="hidden" name="userid" size="20" /> <input type="hidden" name="passwor ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/logout.olamexecute |
GET /olam/logout.olamexecute HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:39:47 GMT Connection: keep-alive Set-Cookie: TLTHID=A313761C71271 Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: EDOCSSESSIONID=h0BxN Set-Cookie: stack=doammw08; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Content-Length: 57599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/registrationAction |
GET /olam/registrationAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:17 GMT Connection: keep-alive Set-Cookie: TLTHID=54B4862A71251 Set-Cookie: EDOCSSESSIONID=1Xg6N Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:17 GMT; path=/ Set-Cookie: stack=p1eam1m6; path=/ Content-Length: 31527 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="/olam/English ...[SNIP]... <noscript><iframe src="https://view.atdmt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/loginAction |
GET /olam/loginAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:12 GMT Connection: keep-alive Set-Cookie: TLTHID=51FED87C71251 Set-Cookie: EDOCSSESSIONID=bcTFN Set-Cookie: stack=doammw31; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:12 GMT; path=/ Content-Length: 57400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... Div").className = ""; } //Below Code added to fix defect WUP00364204 // ISSUE //If user login using wireline id qaywls_3212680090 and rememberme checkbox is checked //then while logout qaywls_3212680090 //In cookie qaywls_3212680090 // code modified for the defect WUP00371849 // Code modified for WUP00364204 defect var tGuardOn = document.loginActionForm var accountType = docum ...[SNIP]... <div id="exampleUverse"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/logout.olamexecute |
GET /olam/logout.olamexecute HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:39:47 GMT Connection: keep-alive Set-Cookie: TLTHID=A313761C71271 Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Set-Cookie: EDOCSSESSIONID=h0BxN Set-Cookie: stack=doammw08; path=/ Set-Cookie: colam_ctn=l%3Den_US; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:39:47 GMT; path=/ Set-Cookie: stack=doammw08; path=/ Content-Length: 57599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... Div").className = ""; } //Below Code added to fix defect WUP00364204 // ISSUE //If user login using wireline id qaywls_3212680090 and rememberme checkbox is checked //then while logout qaywls_3212680090 //In cookie qaywls_3212680090 // code modified for the defect WUP00371849 // Code modified for WUP00364204 defect var tGuardOn = document.loginActionForm var accountType = docum ...[SNIP]... <div id="exampleUverse"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/registrationAction |
GET /olam/registrationAction Host: www.att.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache="set-cookie", no-store Cache-Control: no-cache="set-cookie" Pragma: no-cache Expires: -1 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:17 GMT Connection: keep-alive Set-Cookie: TLTHID=54B4862A71251 Set-Cookie: EDOCSSESSIONID=1Xg6N Set-Cookie: browserid=A001533839947; domain=.att.com; expires=Thursday, 26-Apr-2012 23:23:17 GMT; path=/ Set-Cookie: stack=p1eam1m6; path=/ Content-Length: 31527 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... r wirelesss phone number can contain only numbers. Please verify that the phone number was entered correctly."; map['MemberIDFormatE map['NumberOfCharact map['NumberOfChara ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/tiles/common |
GET /olam/jsp/tiles/common Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 530 Content-Type: text/html; charset=UTF-8 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2CLicense/0 ] X-Powered-By: Servlet/2.5 JSP/2.1 Vary: Accept-Encoding Date: Wed, 27 Apr 2011 23:23:42 GMT Connection: keep-alive Set-Cookie: TLTHID=638F778671251 <html> <body> <form name="myForm"> <input type="hidden" name="userid" size="20" /> <input type="hidden" name="passwor ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://www.att.com |
Path: | /olam/images/attLoader |
GET /olam/images/attLoader Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Length: 5944 Content-Type: image/gif Last-Modified: Thu, 17 Feb 2011 23:19:15 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" x-powered-by: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:57 GMT Connection: keep-alive ......JFIF.....H.H.....C. ........(.....1#%.(:3=<9387 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/AC_RunActiv |
GET /olam/js/AC_RunActiv Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 8029 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:15 GMT Connection: keep-alive //v1.7 // Flash Player Version Detection // Detect Client Browser type // Copyright 2005-2007 Adobe Systems Incorporated. All rights reserved. var isIE = (navigator.appVersion ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/ATT-Olam-english |
GET /olam/js/ATT-Olam-english Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 4261 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:29 GMT Connection: keep-alive // Date last modified = 20090825 // Modified by = DC var lpMTagConfig = { "lpServer" : "sales.liveperson.net", "lpNumber" : "76226072", "lpProtocol" : (document.location.toS ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/Ajax.js |
GET /olam/js/Ajax.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 5717 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:16 GMT Connection: keep-alive var req; var elementToUpdate; function retrieveURL(url, nameOfFormToPost, elementId) { //get the (form based) params to push up as part of the get request //url = url + getFormAsString(nameOfFor ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/UserMessaging.js |
GET /olam/js/UserMessaging.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 451 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:18 GMT Connection: keep-alive function updateUserMessaging var url="/olam/userMessa var form="userMessageAct retrieveURL(url, form, "userMessag ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/cookie.js |
GET /olam/js/cookie.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 10476 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:38 GMT Connection: keep-alive // name - name of the cookie // value - value of the cookie // [expires] - expiration date of the cookie (defaults to end of current session) // [path] - path for which the cookie is valid (defaults t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/cssBrowserS |
GET /olam/js/cssBrowserS Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 564 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:16 GMT Connection: keep-alive var css_browser_selector = function() { var ua=navigator.userAgent is=function(t){return ua.indexOf(t) != -1;}, h=document.getElemen b=(!(/opera|webtv/i.test ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/flash.js |
GET /olam/js/flash.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 9542 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:36 GMT Connection: keep-alive function FlashLibrary(){ var defaultVersion = 8; //SET THIS TO CURRENT VERSION USED BY AT&T var isIE = (navigator.appVersion var isWin = (navigator.appVers ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/gvpUtils.js |
GET /olam/js/gvpUtils.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 35224 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:18 GMT Connection: keep-alive function gvpUtils() { var W3C = (!document.all && document.getElementById); var IE = (document.all); var ns4 = (document.layers); var v_debug = false; var vMainInit = ''; var vBrowBackButStatus ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/hideSelect.js |
GET /olam/js/hideSelect.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 1014 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:16 GMT Connection: keep-alive var isIE6 = navigator.userAgent function hideSelects(){ if(isIE6){ var aSelects = document.getElements var nSelects = aSelects.length; ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/posUtil.js |
GET /olam/js/posUtil.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 175 Accept-Ranges: bytes Last-Modified: Tue, 15 Mar 2011 22:10:40 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:37 GMT Connection: keep-alive /** * validating session time; */ function validateSessionTime() { // 600000 setTimeout('sessionT document.onmousemove = getMousePos; } |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/prototype.js |
GET /olam/js/prototype.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 126127 Accept-Ranges: bytes Last-Modified: Tue, 15 Mar 2011 22:10:40 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:18 GMT Connection: keep-alive /* Prototype JavaScript framework, version 1.6.0.2 * (c) 2005-2008 Sam Stephenson * * Prototype is freely distributable under the terms of an MIT-style license. * For details, see the Prototyp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/registration.js |
GET /olam/js/registration.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 8103 Accept-Ranges: bytes Last-Modified: Tue, 15 Mar 2011 22:10:40 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:42 GMT Connection: keep-alive function trim(str){return str.replace(/^\s*|\s*$/g, function isValidCTN(str){ var re = /(^\d{10}$)/ if (re.test(str)){ return true; } } function isValidMID(str){ /*var re = /^\w+([\+\.-]?\ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/sessionTimeout |
GET /olam/js/sessionTimeout Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 1789 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:16 GMT Connection: keep-alive function sessionTimeoutAlert { var mil = (sessionLength - 2)*60*1000; window.setTimeout( } function alertSessionExpiring() { i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/sniffer.js |
GET /olam/js/sniffer.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 4965 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:34 GMT Connection: keep-alive // sniffer.js Ultimate client-side JavaScript client detection. // (C) Netscape Communications 1999. Permission granted to reuse and distribute. // Revised 08 March 2000 to focus on just Win/Mac & IE ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/tool-tips.js |
GET /olam/js/tool-tips.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 45221 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:44 GMT Connection: keep-alive /* This notice must be untouched at all times. wz_tooltip.js v. 4.12 The latest version is available at http://www.walterzorn.com or http://www.devira.com or http://www.walterzorn.de Copyright (c) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/validate.js |
GET /olam/js/validate.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 24942 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:38 GMT Connection: keep-alive /************************ * * * VALIDATE.JS ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/js/vidSwitcher.js |
GET /olam/js/vidSwitcher.js HTTP/1.1 Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 1287 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:30 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:17 GMT Connection: keep-alive /*----------------------- // vidSwitcher.js // switches parameters for flash embed tag so that a single tag can be reused // ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.att.com |
Path: | /olam/jsp/profile |
GET /olam/jsp/profile Host: www.att.com Connection: keep-alive Referer: https://www.att.com/olam User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=CFC3987A71241 |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Length: 2680 Accept-Ranges: bytes Last-Modified: Wed, 16 Mar 2011 04:31:22 GMT X-Powered-By: Servlet/2.5 JSP/2.1 Date: Wed, 27 Apr 2011 23:23:34 GMT Connection: keep-alive // JavaScript Document var browse; var os; var SafariMacUser = false; var BrowserDetect = { init: function () { this.browser = this.searchString(this browse ...[SNIP]... |