1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
4. Cross-domain Referer leakage
5. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:34:43 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:34:43 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=LPNFFQCT4 Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207601853; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.31 Via: 1.1 12.120.78.31:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... =ProductSub-Category ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Mon, 02 May 2011 00:01:54 GMT Server: Sun-ONE-Web-Server/6.1 Date: Mon, 02 May 2011 00:01:54 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=VYIV31SYK Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207610540; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.79.63 Via: 1.1 12.120.79.63:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... TTCampaign=EMPTY"; _cp_custom_array[n++]= _cp_custom_array[n++]= _cp_custom_array[n++]= _cp_custom_array[n++]= _cp_custom_array[n++]= _cp_custom_array[n++]= /** FR-ABS_0402 Remove Intellakey _cp_cc='ATT'; _cp_pc='ATT101'; _cp_chc='ATT ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Mon, 02 May 2011 00:02:29 GMT Server: Sun-ONE-Web-Server/6.1 Date: Mon, 02 May 2011 00:02:29 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=ZIAJEFC04 Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207579685; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.79.18 Via: 1.1 12.120.79.18:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... <s'+'cript language="javascript" src="http://view.atdmt ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Mon, 02 May 2011 00:01:20 GMT Server: Sun-ONE-Web-Server/6.1 Date: Mon, 02 May 2011 00:01:20 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=LZOJUPGBK Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207610536; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.79.17 Via: 1.1 12.120.79.17:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... <link rel="canonical" href="http://www.business ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:35:06 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:35:06 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=1YST0KTJB Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207610337; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.31 Via: 1.1 12.120.78.31:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... b-Category&repoitem ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:37:46 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:37:46 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=XYNLIASLF Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207601953; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.32 Via: 1.1 12.120.78.32:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... -Category&repoitem=threat ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:32:53 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:32:53 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=WXEJ2N3KR Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207579474; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.32 Via: 1.1 12.120.78.32:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:32:53 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:32:53 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=WXEJ2N3KR Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207579474; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.32 Via: 1.1 12.120.78.32:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:32:53 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:32:53 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=WXEJ2N3KR Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207579474; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.32 Via: 1.1 12.120.78.32:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... </h1> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... </script> <script src="http://www.google ...[SNIP]... </a> <a href="http://www.sbc.com ...[SNIP]... <noscript><img height="1" width="1" src="http://view.atdmt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /enterprise/Family Host: www.business.att.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cust_type=new; svariants=NA; ECOM_GTM=owaln_osaln; bn_u=6923522882713032529; op704wirelesssearchl |
HTTP/1.1 200 OK Last-Modified: Sun, 01 May 2011 23:32:53 GMT Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:32:53 GMT Content-Type: text/html P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private X-atg-version: ATGPlatform/2006.3p5,CAF Set-Cookie: JSESSIONID=WXEJ2N3KR Set-Cookie: JROUTE=p1ba; domain=business.att.com; path=/ Set-Cookie: DYN_USER_ID=207579474; domain=business.att.com; path=/ Set-Cookie: DYN_USER_CONFIRM X-Cache: MISS from 12.120.78.32 Via: 1.1 12.120.78.32:80 (cache/2.6.2.2.16.ATT) Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... </h1> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... </script> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.business.att |
Path: | /enterprise/Family |
GET /robots.txt HTTP/1.0 Host: www.business.att.com |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Sun, 01 May 2011 23:32:54 GMT Content-Length: 256 Content-Type: text P3p: policyref="/w3c/p3p.xml" Cache-Control: max-age=0, proxy-revalidate, private Last-Modified: Tue, 29 Mar 2011 16:21:13 GMT ETag: "4f518-100-4d9206f9" Accept-Ranges: bytes X-Cache: MISS from 12.120.78.33 Via: 1.1 12.120.78.33:80 (cache/2.6.2.2.16.ATT) Connection: keep-alive User-agent: * Disallow: /library/ Disallow: /*online_campaign Disallow: /*online_campaign Disallow: /*online_campaign Disallow: /*online_campaign/tlf/ Disallow: /*ca ...[SNIP]... |